MISP-related products were flagged for a vulnerability affecting website routes used to query external MISP instances, and CERT-PY published an advisory warning organizations about the issue. The exposed functionality involved the /fetch_misp_event and /misp_search_events endpoints, which could be reached without authentication and interacted with remote MISP servers, creating risk around unauthorized use and server-side request handling.
A corresponding code change in MISP/cti-transmute hardened those routes by adding authentication requirements and stricter validation of external MISP URLs. The patch now resolves hostnames to all associated IP addresses and rejects targets if any address is not globally routable, blocking access to private, loopback, link-local, or reserved destinations and reducing SSRF exposure through DNS names; project notes also state that while DNS rebinding or post-validation DNS changes may still allow limited probing, response bodies remain constrained by TLS hostname validation and disabled redirects.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
A code change in MISP/cti-transmute updated MISP URL validation to resolve hostnames and reject non-global IP destinations, and added authentication requirements to the `/fetch_misp_event` and `/misp_search_events` routes. The patch was recorded in commit `4d29109`.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.