CVE-2026-9137
CSP Report Endpoint Log Flooding via Incorrect Size Limit
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.
| CWE | CWE-400 |
| Vendor | misp |
| Product | misp |
| Published | May 20, 2026 |
| Last Updated | May 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for misp misp
Be the first to know when new unknown vulnerabilities affecting misp misp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
misp / misp
2.5.0 โค 2.5.37
References
Credits
Seth Kraft