PT-2026-85050 · Misp · Misp
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
An improper TLS certificate validation issue exists in the
CurlClient component. The CurlClient::$verifyPeer property was not explicitly initialized, defaulting to null, which effectively disabled TLS peer verification during cURL operations unless explicitly enabled by the calling code. This allows HTTPS connections to accept certificates not issued by a trusted certificate authority. A man-in-the-middle attack could be performed by an attacker capable of intercepting network traffic between a MISP instance and a remote HTTPS service to impersonate the endpoint. This could lead to the observation of sensitive information, such as authentication material and threat intelligence, or the modification of responses returned to the MISP instance.Recommendations
Apply the available patch to enable TLS peer verification by default and correct self-signed certificate handling in the
SyncTool component.Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Misp