Improper HTTP-to-HTTPS Redirect in MISP by MISP Project
CVE-2026-67178
7.8HIGH
What is CVE-2026-67178?
The MISP system has a vulnerability in its Apache HTTP virtual-host configuration that can be exploited to perform unintended redirects. Specifically, the generated redirect for HTTP to HTTPS does not include a trailing slash, which can lead to an attacker appending their own content to the hostname. This flaw allows an unauthenticated remote attacker to craft URLs that redirect users to malicious sites. Such exploitation could facilitate phishing attempts or harvest sensitive information. To mitigate this issue, users must update their configurations to ensure that any redirects have a trailing slash, which will prevent unintended path manipulation.
Affected Version(s)
misp 0 < 2.5.41
