CVE-2026-9137
Analyzed
Analyzed - Analysis Complete
Content Security Policy Report Endpoint Log Flooding Vulnerability
Publication date: 2026-05-20
Last updated on: 2026-06-02
Assigner: 5a6e4751-2f3f-4070-9419-94fb35b644e8
Description
Description
The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| misp | misp | From 2.5.0 (inc) to 2.5.38 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |