CVE-2026-69079: CWE-770 Allocation of Resources Without Limits or Throttling in misp cti-transmute
CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a reasonable range. A remote, unauthenticated attacker could submit an excessively large value for this parameter, causing the application to retrieve and process activity data over an arbitrarily large period. This could consume excessive database, CPU, or memory resources, delay the processing of concurrent requests, or trigger an internal server error. Repeated requests could further degrade the availability of the CTI-Transmute website. The vulnerability is corrected by clamping the requested timeline range to a minimum of one day and a maximum of 1,095 days.
AI Analysis
Technical Summary
CVE-2026-69079 is a resource consumption vulnerability (CWE-770) in the CTI-Transmute product by misp, affecting versions up to and including 1.4.0. The unauthenticated /activity_timeline endpoint accepts a 'days' query parameter that is not restricted to a reasonable range. An attacker can supply an excessively large value, causing the application to process activity data over a very large period. This results in excessive consumption of database, CPU, and memory resources, which can delay or disrupt concurrent request processing and potentially cause internal server errors. The vulnerability is mitigated by clamping the requested timeline range to a minimum of one day and a maximum of 1,095 days.
Potential Impact
An unauthenticated remote attacker can exploit this vulnerability to cause excessive resource consumption on the CTI-Transmute server. This can degrade the availability and responsiveness of the service by overloading database, CPU, and memory resources. Repeated exploitation attempts could lead to denial of service conditions or internal server errors, impacting legitimate users.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability is known to be corrected by limiting the 'days' parameter to a range between one and 1,095 days. Until an official fix or update is available, consider implementing request rate limiting or input validation on the 'days' parameter to restrict excessively large values.
CVE-2026-69079: CWE-770 Allocation of Resources Without Limits or Throttling in misp cti-transmute
Description
CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a reasonable range. A remote, unauthenticated attacker could submit an excessively large value for this parameter, causing the application to retrieve and process activity data over an arbitrarily large period. This could consume excessive database, CPU, or memory resources, delay the processing of concurrent requests, or trigger an internal server error. Repeated requests could further degrade the availability of the CTI-Transmute website. The vulnerability is corrected by clamping the requested timeline range to a minimum of one day and a maximum of 1,095 days.
CVSS v4.0
Score 8.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-69079 is a resource consumption vulnerability (CWE-770) in the CTI-Transmute product by misp, affecting versions up to and including 1.4.0. The unauthenticated /activity_timeline endpoint accepts a 'days' query parameter that is not restricted to a reasonable range. An attacker can supply an excessively large value, causing the application to process activity data over a very large period. This results in excessive consumption of database, CPU, and memory resources, which can delay or disrupt concurrent request processing and potentially cause internal server errors. The vulnerability is mitigated by clamping the requested timeline range to a minimum of one day and a maximum of 1,095 days.
Potential Impact
An unauthenticated remote attacker can exploit this vulnerability to cause excessive resource consumption on the CTI-Transmute server. This can degrade the availability and responsiveness of the service by overloading database, CPU, and memory resources. Repeated exploitation attempts could lead to denial of service conditions or internal server errors, impacting legitimate users.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability is known to be corrected by limiting the 'days' parameter to a range between one and 1,095 days. Until an official fix or update is available, consider implementing request rate limiting or input validation on the 'days' parameter to restrict excessively large values.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CIRCL
- Date Reserved
- 2026-08-03T09:20:23.702Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a706affbf32cb7a346e0b5c
Added to database: 08/03/2026, 10:18:39 UTC
Last enriched: 08/03/2026, 10:33:00 UTC
Last updated: 08/03/2026, 11:33:30 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.