Executive brief
MISP Modules, a set of expansion tools for the MISP threat intelligence platform, contains vulnerabilities in how it fetches remote data. These flaws could allow an attacker to probe internal network resources or intercept sensitive data during image retrieval. This could lead to the exposure of internal infrastructure details or the tampering of information being processed by the platform.
Technical details
Two distinct vulnerabilities exist in MISP Modules expansion modules. The 'html_to_markdown' module is vulnerable to Server-Side Request Forgery (SSRF) because it accepts arbitrary HTTP(S) URLs without validating against loopback, private, or link-local address ranges. Separately, the 'qrcode' module fails to verify TLS certificates when fetching remote images (CWE-295), enabling man-in-the-middle (MitM) attacks. An attacker can exploit these to access internal services or intercept/tamper with remote resources. The issues were addressed in the 01a522f commit by implementing URL scheme validation, IP blacklisting, and re-enabling TLS verification.
Affected products
- MISP Project misp-modules <= 3.0.7
Timeline
- 2026-04-29: disclosed: Initial disclosure to MISP/misp-modules
- 2026-05-06: advisory: GitHub Advisory published
- 2026-05-13: advisory: NVD published CVE-2026-44363