Improper HTTP-to-HTTPS Redirect in MISP by MISP Project
CVE-2026-67178

7.8HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-67178?

The MISP system has a vulnerability in its Apache HTTP virtual-host configuration that can be exploited to perform unintended redirects. Specifically, the generated redirect for HTTP to HTTPS does not include a trailing slash, which can lead to an attacker appending their own content to the hostname. This flaw allows an unauthenticated remote attacker to craft URLs that redirect users to malicious sites. Such exploitation could facilitate phishing attempts or harvest sensitive information. To mitigate this issue, users must update their configurations to ensure that any redirects have a trailing slash, which will prevent unintended path manipulation.

Affected Version(s)

misp 0 < 2.5.41

References

CVSS V4

Score:
7.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
Jeroen Pinoy
.