Executive brief
MISP is an open-source platform used by organizations to share and analyze threat intelligence. A vulnerability in the platform's 'Collections' feature allowed users to save records with improperly formatted identification numbers (UUIDs). This could lead to data integrity issues or cause the system to behave unexpectedly when processing these records, potentially disrupting intelligence sharing operations.
Technical details
An improper input validation vulnerability (CWE-20) exists in MISP prior to version 2.5.37 within the Collections component. The application failed to validate the 'uuid' field against the RFC 4122 standard during record creation or modification. An authenticated attacker with permissions to manage Collections can submit arbitrary strings in place of valid UUIDs. This can cause downstream logic errors or database integrity issues in components that assume these identifiers are strictly formatted. The issue was resolved in version 2.5.37 by implementing model-level validation in app/Model/Collection.php.
Affected products
- MISP Project MISP < 2.5.37
Timeline
- 2026-04-29: advisory: GitHub Security Advisory published
- 2026-05-13: disclosed: CVE published to NVD
- 2026-05-13: patched: Fixed in version 2.5.37