CVE-2026-92003
MISP Unthrottled Authentication Failure Log Writes Enable Resource Exhaustion
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model: โ- API requests with no authentication key; โ- requests supplying an API key with an incorrect length Unlike other authentication failures, these paths bypassed _shouldLog(), so every request could create another durable auth_fail entry. Version affected: โค2.5.45
| CWE | CWE-770 CWE-400 |
| Vendor | misp |
| Product | misp |
| Published | Sep 15, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for misp misp
Be the first to know when new unknown vulnerabilities affecting misp misp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
MISP / MISP
0 < 2.5.46
References
Credits
iglocska Claude Opus 5 (1M context)