Description
Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle.


Two API authentication failure branches wrote directly to the Log model:

 - API requests with no authentication key;
 - requests supplying an API key with an incorrect length




Unlike other authentication failures, these paths bypassed _shouldLog(), so every request could create another durable auth_fail entry.

Version affected: ≤2.5.45
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability exists in MISP versions earlier, where two API authentication failure paths bypass the existing throttling mechanism. As a result, each failed authentication attempt that carries either no API key or an entry to the Log model without any rate limit. The infinite log generation can consume disk space or database resources denial of service. This represents an input validation weakness (CWE‐400) and a memory exhaustion flaw (CWE‐770).

Affected Systems

Affected systems are deployments of the MISP open‑source platform with a version of 2.5.45 or older. The affected vendor and product are MISP: MISP. No additional sub‑versions are listed in the CNA data.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score of less than 1% suggests a low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is readily exploitable via the public API endpoints: requests with either no API key or a key of incorrect length from any IP address, creating a log entry each time. Because the attacker controls the source IP, the throttle key is also controllable, allowing the attacker to bypass any per‑IP limits until the fix is applied. This could exhaust disk or database capacity and cause a denial of service.

Generated by OpenCVE AI on September 17, 2026 at 17:29 UTC.

Remediation

Vendor Solution

The fix applies the existing hourly per-key log throttle to the two previously unguarded authentication-failure log writes. The throttle key is now derived from the client's source IP address rather than from caller-supplied input, preventing an attacker from generating unbounded Redis throttle entries. A per-request memo (stored in Configure::read('CurrentRequestAuthFailKeys')) is added to _shouldLog() to prevent duplicate log entries when beforeFilter() executes a second time via CakeErrorController on an exception, ensuring one request produces at most one log entry per key regardless of the operator's log_each_individual_auth_fail setting.


OpenCVE Recommended Actions

  • Apply the patch that restores throttling for authentication‑failure log writes (found in commit 2bf887433) or upgrade to MISP 2.5.46 or later.
  • Ensure the throttle key is derived from the client source IP and that Configure::read('CurrentRequestAuthFailKeys') holds a per‑request memo to prevent duplicate log entries.
  • Deploy an API rate limiter or firewall rule to limit the rate of authentication requests per IP, reducing the chance of resource exhaustion.

Generated by OpenCVE AI on September 17, 2026 at 17:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Misp
Misp misp
Vendors & Products Misp
Misp misp

Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model:  - API requests with no authentication key;  - requests supplying an API key with an incorrect length Unlike other authentication failures, these paths bypassed _shouldLog(), so every request could create another durable auth_fail entry. Version affected: ≤2.5.45
Title MISP Unthrottled Authentication Failure Log Writes Enable Resource Exhaustion
Weaknesses CWE-400
CWE-770
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-09-15T12:32:06.515Z

Reserved: 2026-09-15T11:43:17.522Z

Link: CVE-2026-92003

cve-icon Vulnrichment

Updated: 2026-09-15T12:32:01.287Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T12:17:55.757

Modified: 2026-09-16T13:42:48.523

Link: CVE-2026-92003

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:15:13Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling