CVE-2026-76821
Awaiting Analysis Awaiting Analysis - Queue

ReDoS in OpenCTI JSON Mapper via Catastrophic Backtracking

Vulnerability report for CVE-2026-76821, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260706.0, the JSON ingestion mapper's extractWithRegexp formula function compiled a user-supplied regular expression with the JavaScript RegExp engine in opencti-platform/opencti-graphql/src/parser/json-mapper.ts without validating its complexity. An authenticated user with JSON mapper creation permission could provide a catastrophically backtracking pattern and matching ingestion input, blocking the Node.js event loop and making the GraphQL API unavailable to all users. Scheduled ingestion could repeatedly execute the malicious mapper without additional attacker action, and recovery could require disabling the mapper and restarting the process. The issue affects availability and does not expose or modify data. This issue is fixed in version 7.260706.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-30
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
opencti opencti to 7.260706.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1333 The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Regular Expression Denial of Service (ReDoS) vulnerability in OpenCTI's JSON ingestion mapper. An authenticated user with JSON mapper creation permissions could provide a malicious regular expression that causes catastrophic backtracking when executed. This freezes the Node.js event loop, making the GraphQL API unavailable to all users.

Detection Guidance

To detect this vulnerability, monitor for unusually high CPU usage or unresponsive GraphQL API endpoints in OpenCTI. Check for malicious regex patterns in JSON mappers created by users with mapper creation permissions. Use system monitoring tools like top, htop, or ps to observe Node.js process behavior during ingestion tasks.

Impact Analysis

The vulnerability allows an attacker to disrupt the entire OpenCTI platform by freezing the GraphQL API. Scheduled ingestion processes would repeatedly trigger the malicious mapper, causing recurring downtime. Recovery requires manually disabling the mapper and restarting the Node.js process. No data is exposed or modified, only system availability is affected.

Compliance Impact

This vulnerability primarily impacts availability by causing denial of service through resource exhaustion. It does not expose or modify data, so direct impacts on GDPR or HIPAA compliance are limited. However, prolonged system unavailability could disrupt access to personal data or health information, potentially violating availability requirements under these regulations.

Mitigation Strategies

Upgrade OpenCTI to version 7.260706.0 or later to apply the fix. Disable any suspicious JSON mappers created by users with mapper creation permissions. Restart the Node.js process to clear any ongoing regex backtracking issues. Review and audit all JSON mappers for complex or malicious regex patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76821. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart