Server-Side Request Forgery Vulnerability in MISP by MISP Project
CVE-2026-86419
What is CVE-2026-86419?
Versions of MISP prior to 2.5.46 contain a vulnerability that allows for insecure handling of server-side outbound HTTP destinations during feed retrieval and TAXII discovery. The vulnerability arises from insufficient validation of redirects, which can enable malicious redirection to unauthorized internal resources, exposing sensitive API credentials or other authentication headers. The fixes implemented restrict redirects through validation measures and prevent internal access, thus protecting against potential SSRF attacks and preserving credential integrity. The TAXII discovery process also receives updates to enhance its defenses against various address representations and unsafe redirects.
Affected Version(s)
MISP 0 <= 2.5.45
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
