CVE 5.1 MEDIUM

CSP Report Endpoint Log Flooding via Incorrect Size Limit_CVE-2026-9137

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Description

The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.

Basic Information

ID CVE-2026-9137
Source CIRCL
Published May 20, 2026 at 18:43

Affected Product

Vendor misp
Product misp
Version 2.5.0
Affected Versions misp misp 2.5.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.