The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 29 May 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding. | The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding. |
| Title | CSP Report Endpoint Log Flooding via Incorrect Size Limit | CSP Report Endpoint Log Flooding in MISP via Incorrect Size Limit |
Wed, 20 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Misp
Misp misp |
|
| Vendors & Products |
Misp
Misp misp |
Wed, 20 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding. | |
| Title | CSP Report Endpoint Log Flooding via Incorrect Size Limit | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CIRCL
Published: 2026-05-20T18:43:30.895Z
Updated: 2026-05-29T06:57:50.739Z
Reserved: 2026-05-20T18:42:18.665Z
Link: CVE-2026-9137
Updated: 2026-05-20T19:26:42.606Z
Status : Analyzed
Published: 2026-05-20T20:16:46.177
Modified: 2026-06-02T16:34:32.473
Link: CVE-2026-9137
No data.