Description
A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules.

The module attempts to prevent requests to loopback, private, link-local, and other restricted IP address ranges. However, IP addresses were compared against the blocked ranges without first normalising IPv4-mapped IPv6 addresses.

An authenticated attacker able to invoke the module could supply an IPv4-mapped IPv6 address, such as:

http://[::ffff:127.0.0.1]/
http://[::ffff:169.254.169.254]/

Alternatively, the attacker could use a hostname that resolves to an IPv4-mapped IPv6 address. These addresses were treated as IPv6 addresses and therefore did not match the corresponding blocked IPv4 ranges.

Successful exploitation could cause the misp-modules server to connect to services available through its loopback interface, internal network, or link-local network. This could expose internal web services, administrative interfaces, or cloud instance metadata, with retrieved content potentially returned to the attacker as converted Markdown.

The vulnerability has been addressed by normalising IPv4-mapped IPv6 addresses to their underlying IPv4 representation before applying the blocked-range checks. URLs without a valid hostname are now also rejected.
Published: 2026-07-13
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A Server‑Side Request Forgery protection bypass exists in the html_to_markdown module of misp-modules. The module verifies URLs against blocked IP ranges but fails to normalize IPv4‑mapped IPv6 addresses. An authenticated attacker can supply a URL such as http://[::ffff:127.0.0.1]/ or a hostname resolving to an IPv4‑mapped IPv6 address, causing the server to resolve and connect to services on its loopback, internal, or link‑local interfaces. The content retrieved from those services is then converted to Markdown and returned to the attacker, exposing internal web services, administrative interfaces, or cloud instance metadata. This flaw corresponds to the common weakness enumeration CWE-918, reflecting a Server‑Side Request Forgery vulnerability.

Affected Systems

All installations of the MISP platform that include the misp-modules html_to_markdown extension are affected, specifically those running a module version before the patch referenced by commit 3bae4108a3ba1e507727d5264697fd7303ba0b89. The vulnerability can be exploited only by authenticated users with permission to invoke the module.

Risk and Exploitability

The CVSS base score is 8.3, indicating high severity. The EPSS score is reported as < 1%, suggesting a very low probability of exploitation in observed traffic, and the vulnerability is not listed in the CISA KEV catalog. The attack requires authenticated access to the module and the ability to supply a crafted URL. Successful exploitation can lead to read access to internal interfaces, cloud metadata, or enable further lateral attacks. The attack surface is limited to the outbound fetch capability of the module.

Generated by OpenCVE AI on August 1, 2026 at 10:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade misp-modules to a version that includes commit 3bae4108a3ba1e507727d5264697fd7303ba0b89 or later, which normalizes IPv4‑mapped IPv6 addresses before performing blocked‑range checks.
  • If the html_to_markdown functionality is not required, disable or restrict its ability to fetch external URLs by configuring the module settings or applying API restrictions.
  • Implement network‑level controls such as firewall rules or segmentation to block outbound connections from the misp-modules server to internal or cloud‑metadata hosts, limiting the attack surface.

Generated by OpenCVE AI on August 1, 2026 at 10:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp-modules
Vendors & Products Misp
Misp misp-modules

Mon, 13 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Description A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules. The module attempts to prevent requests to loopback, private, link-local, and other restricted IP address ranges. However, IP addresses were compared against the blocked ranges without first normalising IPv4-mapped IPv6 addresses. An authenticated attacker able to invoke the module could supply an IPv4-mapped IPv6 address, such as: http://[::ffff:127.0.0.1]/ http://[::ffff:169.254.169.254]/ Alternatively, the attacker could use a hostname that resolves to an IPv4-mapped IPv6 address. These addresses were treated as IPv6 addresses and therefore did not match the corresponding blocked IPv4 ranges. Successful exploitation could cause the misp-modules server to connect to services available through its loopback interface, internal network, or link-local network. This could expose internal web services, administrative interfaces, or cloud instance metadata, with retrieved content potentially returned to the attacker as converted Markdown. The vulnerability has been addressed by normalising IPv4-mapped IPv6 addresses to their underlying IPv4 representation before applying the blocked-range checks. URLs without a valid hostname are now also rejected.
Title Server-Side Request Forgery protection bypass in misp-modules html_to_markdown via IPv4-mapped IPv6 addresses
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/AU:Y/RE:M/U:Green'}


Subscriptions

Misp Misp-modules
cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-07-14T14:32:41.437Z

Reserved: 2026-07-13T07:52:02.284Z

Link: CVE-2026-62143

cve-icon Vulnrichment

Updated: 2026-07-14T14:16:48.193Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:00:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)