CVE-2026-62143: CWE-918 Server-Side Request Forgery (SSRF) in misp misp-modules
CVE-2026-62143 is a Server-Side Request Forgery (SSRF) vulnerability in the html_to_markdown expansion module of misp-modules. The module failed to normalize IPv4-mapped IPv6 addresses before checking them against blocked IP ranges, allowing an authenticated attacker to bypass SSRF protections. This could enable the attacker to make the server connect to internal services such as loopback, private, or link-local network addresses. The vulnerability has been fixed by normalizing IPv4-mapped IPv6 addresses and rejecting URLs without valid hostnames.
AI Analysis
Technical Summary
The SSRF protection bypass in misp-modules' html_to_markdown expansion module arises because IP addresses were checked against restricted ranges without normalizing IPv4-mapped IPv6 addresses to their IPv4 equivalents. Attackers with authentication could supply URLs using IPv4-mapped IPv6 notation (e.g., http://[::ffff:127.0.0.1]/) or hostnames resolving to such addresses, which were incorrectly treated as IPv6 and thus not blocked. This allowed the server to connect to internal network services, potentially exposing sensitive internal web services, administrative interfaces, or cloud metadata endpoints. The issue was remediated by normalizing these addresses before applying blocked-range checks and rejecting URLs lacking valid hostnames.
Potential Impact
An authenticated attacker can bypass SSRF protections to make the misp-modules server connect to internal or restricted network services, potentially exposing sensitive internal resources such as administrative interfaces or cloud instance metadata. This could lead to unauthorized information disclosure. The vulnerability has a high severity score (CVSS 8.3).
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability description states it has been addressed by normalizing IPv4-mapped IPv6 addresses and rejecting invalid hostnames. Until an official fix is confirmed, restrict access to the vulnerable module to trusted users only and monitor for suspicious activity.
CVE-2026-62143: CWE-918 Server-Side Request Forgery (SSRF) in misp misp-modules
Description
CVE-2026-62143 is a Server-Side Request Forgery (SSRF) vulnerability in the html_to_markdown expansion module of misp-modules. The module failed to normalize IPv4-mapped IPv6 addresses before checking them against blocked IP ranges, allowing an authenticated attacker to bypass SSRF protections. This could enable the attacker to make the server connect to internal services such as loopback, private, or link-local network addresses. The vulnerability has been fixed by normalizing IPv4-mapped IPv6 addresses and rejecting URLs without valid hostnames.
CVSS v4.0
Score 8.3high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The SSRF protection bypass in misp-modules' html_to_markdown expansion module arises because IP addresses were checked against restricted ranges without normalizing IPv4-mapped IPv6 addresses to their IPv4 equivalents. Attackers with authentication could supply URLs using IPv4-mapped IPv6 notation (e.g., http://[::ffff:127.0.0.1]/) or hostnames resolving to such addresses, which were incorrectly treated as IPv6 and thus not blocked. This allowed the server to connect to internal network services, potentially exposing sensitive internal web services, administrative interfaces, or cloud metadata endpoints. The issue was remediated by normalizing these addresses before applying blocked-range checks and rejecting URLs lacking valid hostnames.
Potential Impact
An authenticated attacker can bypass SSRF protections to make the misp-modules server connect to internal or restricted network services, potentially exposing sensitive internal resources such as administrative interfaces or cloud instance metadata. This could lead to unauthorized information disclosure. The vulnerability has a high severity score (CVSS 8.3).
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability description states it has been addressed by normalizing IPv4-mapped IPv6 addresses and rejecting invalid hostnames. Until an official fix is confirmed, restrict access to the vulnerable module to trusted users only and monitor for suspicious activity.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CIRCL
- Date Reserved
- 2026-07-13T07:52:02.284Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a54a64468715ace43837a22
Added to database: 07/13/2026, 08:48:04 UTC
Last enriched: 07/20/2026, 19:18:21 UTC
Last updated: 08/27/2026, 05:32:35 UTC
Views: 112
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.