← Zurück zur CVE-Suche

CVE-2026-9137

CSP report endpoint

Beschreibung

The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.

CVSS 7.5EPSS 0.365%Risiko 0.77
Quelle öffnen
Veröffentlicht
2026-05-20 20:16:46
Betroffene Versionen
unknown
Typ
Core software
Zuletzt geändert
2026-07-23 15:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H