Server-Side Request Forgery Vulnerability in MISP by MISP Project
CVE-2026-86419

7HIGH

Key Information:

Vendor

Misp

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86419?

Versions of MISP prior to 2.5.46 contain a vulnerability that allows for insecure handling of server-side outbound HTTP destinations during feed retrieval and TAXII discovery. The vulnerability arises from insufficient validation of redirects, which can enable malicious redirection to unauthorized internal resources, exposing sensitive API credentials or other authentication headers. The fixes implemented restrict redirects through validation measures and prevent internal access, thus protecting against potential SSRF attacks and preserving credential integrity. The TAXII discovery process also receives updates to enhance its defenses against various address representations and unsafe redirects.

Affected Version(s)

MISP 0 <= 2.5.45

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Scottish Government - National Cyber Team
iglocska
Claude Opus 5 (1M context)
.