Description
Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality.


In feed processing, redirects were followed without validating the redirect scheme or destination. The original request headers were reused across redirect hops, meaning authentication headers or API credentials configured for a feed could be forwarded to a different host. Redirects could also target internal network resources, resulting in SSRF. The fix adds redirect validation, blocks internal destinations for cross-host redirects, strips configured feed credentials before following redirects to another host, and pins validated DNS results to prevent re-resolution after validation.


The TAXII discovery endpoint had a related incomplete SSRF defense. It used gethostbyname() and compared the result against only a few literal addresses. This missed cases including IPv6 loopback (::1), numeric host encodings such as 0x7f000001, and potentially multiple DNS records. The fix moves TAXII discovery to the shared URL egress validator.


Together, these commits harden MISP's outbound URL handling against alternate-address representations, DNS-related bypasses, unsafe redirects, internal-host access, and cross-host credential forwarding.






Version affected: ≤2.5.45
Published: 2026-09-07
Score: 7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Affected MISP versions allow outbound HTTP requests to untrusted destinations during feed retrieval and TAXII discovery. Redirects are followed without validating the scheme or target, and authentication headers can be stolen and reused against another host. The lack of internal destination checks also permits a remote attacker to trigger server‑side request forgery, reaching internal services and exposing credentials.

Affected Systems

MISP – Versions 2.5.45 and earlier.

Risk and Exploitability

The CVSS score of 7.0 indicates a medium‑to‑high severity vulnerability. EPSS is not available, and the issue is not listed in CISA’s KEV catalog. The described weaknesses allow a remote attacker, for example by configuring a malicious feed URL or manipulating the TAXII discovery endpoint, to perform SSRF against internal resources or to cause credentials to be forwarded to an external party. If the attacker controls the redirect target, they can direct requests to any host reachable from the MISP server.

Generated by OpenCVE AI on September 7, 2026 at 14:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MISP to version 2.5.46 or later, which includes redirect validation, internal‑host blocking, and credential stripping.
  • Configure MISP to disable automatic redirects or enforce strict HTTPS connections when retrieving feeds.
  • Restrict outgoing HTTP traffic from the MISP server to only trusted hosts, possibly via firewall rules or egress controls.
  • Monitor MISP logs for unexpected outbound HTTP requests and credential usage to detect any remaining SSRF attempts.

Generated by OpenCVE AI on September 7, 2026 at 14:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp
Vendors & Products Misp
Misp misp

Mon, 07 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme or destination. The original request headers were reused across redirect hops, meaning authentication headers or API credentials configured for a feed could be forwarded to a different host. Redirects could also target internal network resources, resulting in SSRF. The fix adds redirect validation, blocks internal destinations for cross-host redirects, strips configured feed credentials before following redirects to another host, and pins validated DNS results to prevent re-resolution after validation. The TAXII discovery endpoint had a related incomplete SSRF defense. It used gethostbyname() and compared the result against only a few literal addresses. This missed cases including IPv6 loopback (::1), numeric host encodings such as 0x7f000001, and potentially multiple DNS records. The fix moves TAXII discovery to the shared URL egress validator. Together, these commits harden MISP's outbound URL handling against alternate-address representations, DNS-related bypasses, unsafe redirects, internal-host access, and cross-host credential forwarding. Version affected: ≤2.5.45
Title MISP Insufficient Outbound URL Validation Allows SSRF and Credential Disclosure via Feed Redirects and TAXII Discovery
Weaknesses CWE-200
CWE-918
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-07T12:31:35.184Z

Reserved: 2026-09-07T12:31:32.941Z

Link: CVE-2026-86419

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T13:20:40.663

Modified: 2026-09-07T13:20:40.663

Link: CVE-2026-86419

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T14:15:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-918

    Server-Side Request Forgery (SSRF)