๐Ÿ” CVE Alert

CVE-2026-9137

UNKNOWN 0.0

CSP Report Endpoint Log Flooding via Incorrect Size Limit

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.

CWE CWE-400
Vendor misp
Product misp
Published May 20, 2026
Last Updated May 20, 2026
Stay Ahead of the Next One

Get instant alerts for misp misp

Be the first to know when new unknown vulnerabilities affecting misp misp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

misp / misp
2.5.0 โ‰ค 2.5.37

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MISP/MISP/commit/02932cccab230b295afcaf5aa05e363d30db0ec9

Credits

Seth Kraft