MISP Collections UUID Validation Flaw in Open Source Threat Intelligence Platform
CVE-2026-44379

5.3MEDIUM

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
13 May 2026

What is CVE-2026-44379?

The MISP platform, designed for threat intelligence sharing, previously allowed users to submit malformed UUID values when creating or modifying Collection records due to a lack of enforcement for RFC 4122 compliance. This oversight posed risks including potential integrity issues or unexpected behaviors in processes that depend on valid UUIDs. The issue has been addressed in version 2.5.37, which incorporates proper validation checks for UUID inputs.

Affected Version(s)

MISP < 2.5.37

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.