CVE-2026-77761: CWE-459 Incomplete Cleanup in misp misp-stix
Description
CVE-2026-77761 is a parser state isolation vulnerability in the misp-stix component of MISP. It causes data from a previously processed STIX document to be retained and mixed into subsequent MISP events when the same parser instance is reused. This affects STIX 1 and STIX 2 parsers, leading to incorrect associations and potential limited information disclosure between events. The vulnerability requires reuse of parser instances and specific document ordering, increasing exploitation complexity. There is no impact on availability or code execution.
CVSS v4.0
Score 6.3medium
Affected software
misp
misp-stix
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in misp-stix arises from incomplete cleanup of parser state between processing STIX documents. Several STIX 1 and STIX 2 parser components maintain per-document state that is not fully cleared on reuse. In STIX 2, galaxy and galaxy-cluster data, including custom clusters, can persist after a parser reset and be incorrectly associated with objects from a different bundle. STIX 1 parsers similarly retain galaxies, references, passive DNS data, package titles, dates, and timestamps. This causes subsequent MISP events generated by the reused parser to contain data from previously processed documents, potentially contaminating threat intelligence with unrelated or misleading information. The issue primarily affects applications that reuse parser instances via the misp-stix API rather than those that instantiate a new parser per document. Exploitation requires control over the documents processed by a long-lived parser and depends on document ordering.
Potential Impact
The vulnerability can compromise the integrity of threat intelligence by causing MISP events to include data from unrelated STIX documents. This may lead to incorrect associations, misleading contextual information, or unrelated indicators being attributed to events. In environments with different access controls or distribution scopes for consecutive documents, there is a risk of limited disclosure of information from previously processed documents. There is no impact on system availability or code execution. Exploitation complexity is increased due to the need for parser reuse and document ordering.
Mitigation Recommendations
No official patch or fix is currently documented. The vulnerability primarily affects applications that reuse the same parser instance for multiple STIX documents. Mitigation involves ensuring that a new parser instance is created for each STIX document processed, avoiding reuse of parser instances. Users should review their use of the misp-stix API to confirm that parser instances are not reused across independent documents. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CIRCL
- Date Reserved
- 2026-08-21T10:11:49.766Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8826fcacd9273b49fcf5f9
Added to database: 08/21/2026, 10:22:52 UTC
Last enriched: 09/11/2026, 03:04:22 UTC
Last updated: 10/05/2026, 06:48:18 UTC
Views: 85
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.