Executive brief
MISP-STIX is a library used to import threat intelligence data in STIX format into MISP, a threat intelligence platform. A vulnerability allows attackers to disrupt the import process by providing malformed or oversized STIX documents, causing the importer to crash abnormally or consume excessive memory and CPU resources, potentially disrupting security operations that depend on automated threat data ingestion.
Technical details
The vulnerability consists of two denial-of-service conditions in the STIX import code. First, the library calls sys.exit() to handle parsing and loading failures; since SystemExit inherits from BaseException rather than Exception, these calls bypass exception handlers in calling code, causing uncaught process termination. Second, no size limit is enforced on STIX documents before parsing; malformed or intentionally large documents are fully read into memory and deserialized before validation, causing memory consumption up to 7× the input size. An attacker able to submit STIX documents to an import workflow can exploit either condition to terminate importer processes or exhaust system resources. Patches replace sys.exit() calls with catchable exceptions, implement comprehensive exception handling, and enforce a default 100 MB input-size limit that can be adjusted or disabled by callers.
Affected products
- MISP Project misp-stix
Timeline
- 2026-08-21: disclosed