CVE Database
/

CVE-2026-9137

Back to search

CVE-2026-9137

Published: May 20, 2026

Modified: May 29, 2026

PUBLISHED

Description

The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.

VendorProductVersions

misp

misp

affected
2.5.0 - <= 2.5.37

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now