CVE-2026-9137

The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.
Configurations

Configuration 1 (hide)

cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*

History

02 Jun 2026, 16:34

Type Values Removed Values Added
First Time Misp
Misp misp
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:*
References () https://github.com/MISP/MISP/commit/02932cccab230b295afcaf5aa05e363d30db0ec9 - () https://github.com/MISP/MISP/commit/02932cccab230b295afcaf5aa05e363d30db0ec9 - Patch

29 May 2026, 08:16

Type Values Removed Values Added
Summary (en) The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding. (en) The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.

20 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-20 20:16

Updated : 2026-06-02 16:34


NVD link : CVE-2026-9137

Mitre link : CVE-2026-9137

CVE.ORG link : CVE-2026-9137


JSON object : View

Products Affected

misp

  • misp
CWE
CWE-400

Uncontrolled Resource Consumption