CVE-2026-86452CWE-400CWE-770

MISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request Flooding

High · published September 7, 2026

CVSS v4.0
8.7
EPSS
In the wild
Unconfirmed
What it is

Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting.

The users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a reasonable length bound or validating its format. That value was then used to create an audit log entry and queue a password-reset job, causing the supplied value to be persisted more than once per request. The commit explicitly states that an unbounded unauthenticated request field was stored twice per call with no throttle.

The fix adds:

*

a maximum email input length of 1024 bytes;

*

email-format validation before persistent work;

*

a per-source pre-authentication request budget;

*

HTTP 429 responses when that budget is exceeded;

*

a 15-minute cooldown for API-access request emails;

*

POST-only handling and CSRF protection for the API-access request endpoint.

The new flood filter is specifically intended to limit persistent storage costs from anonymous requests such as password resets, registrations, and failed REST authentication attempts.

Version affected: ≤2.5.45

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
Not scored
Weaknesses
CWE-400 · Uncontrolled Resource Consumption; CWE-770 · Allocation of Resources Without Limits or Throttling
Published
2026-09-07T13:03Z
Timeline
  • 07 SEP 13:03Z
    MISP Unauthenticated Mail Endpoints Allow Unbounded Storage Consumption and Request Flooding
    cvelistv5