受影响版本的 MISP 未能一致地应用现有的认证失败日志记录限流机制。 两个 API 认证失败的分支直接写入了 Log 模型: 未提供认证密钥的 API 请求; 提供了长度不正确的 API 密钥的请求。 与其他认证失败情形不同,这些代码路径绕过了 函数,因此每个请求都可能创建一条新的持久化 日志条目。 受影响版本:≤ 2.5.45
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-91825 | 7.1 HIGH | MISP: Missing Authorization Check for Event Sharing Group When Distribution Field Is Omitt |
| CVE-2026-91846 | 7.1 HIGH | MISP Collection Element Add Missing Authorization on Referenced Object UUID |
| CVE-2026-91819 | 6.9 MEDIUM | MISP: HTTP Method Override Bypasses CSRF and Form Validation in BetterSecurityComponent |
| CVE-2026-91851 | 5.3 MEDIUM | MISP Dashboard Template ACL Bypass Due to VARCHAR-to-Integer Type Coercion in Permission F |
| CVE-2026-91857 | 5.3 MEDIUM | MISP: State-changing actions accessible via GET request enabling CSRF |
| CVE-2026-91859 | 5.3 MEDIUM | MISP Access Log Entry Overwritten by Error Controller's Second beforeFilter Pass |
| CVE-2026-92002 | 5.1 MEDIUM | MISP: Authentication failure logging suppressed during Redis unavailability |
No comments yet