CVE-2026-77761: CWE-459 Incomplete Cleanup in misp misp-stix
A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into the MISP event generated from a subsequent document when the same parser instance is reused. Several STIX 1 and STIX 2 parser components maintained per-document state that was not completely cleared between conversions. In the STIX 2 parser, galaxy and galaxy-cluster information, including custom galaxy clusters, could survive a parser reset and subsequently be associated with objects from another bundle. The STIX 1 parsers were affected by the same underlying state-management issue. Depending on the parser type, retained information could include galaxies, references, passive DNS bookkeeping, package titles, dates, and timestamps. As a result, parsing a second STIX package with an already-used parser could produce a MISP event containing information that was present only in the previously processed package. For example, a generated event could inherit passive DNS records from an earlier document, reference unrelated galaxy information, combine titles from different packages, or use timestamps originating from another conversion. The issue primarily affects applications using the misp-stix API directly and reusing parser instances across independent STIX documents. Normal conversion entry points that instantiate a new parser for each file are not affected by this particular reuse scenario. An attacker able to influence documents processed by such a long-lived parser could potentially cause information from one conversion to contaminate a subsequent MISP event. This can affect the integrity of generated threat intelligence, resulting in incorrect associations, misleading contextual information, or unrelated indicators being attributed to an event. In environments where consecutive documents have different access controls or distribution scopes, the retained state could additionally result in limited disclosure of information from a previously processed document. Successful exploitation depends on the consuming application reusing the same parser instance and on the ordering of processed documents, which increases attack complexity. No direct availability impact or code execution is involved.
AI Analysis
Technical Summary
The vulnerability in misp-stix arises from incomplete cleanup of parser state between processing STIX documents. Several parser components maintain per-document state that is not fully cleared upon parser reuse. In STIX 2 parsers, galaxy and galaxy-cluster data, including custom clusters, may persist and be incorrectly associated with new objects. STIX 1 parsers suffer from similar issues with retained galaxies, references, passive DNS data, titles, dates, and timestamps. This causes subsequent MISP events generated from reused parsers to contain data from previously processed documents, potentially misleading threat intelligence analysis or causing unauthorized information disclosure. The issue requires reuse of the same parser instance and specific document ordering, increasing exploitation complexity. There is no impact on availability or code execution.
Potential Impact
The vulnerability can cause contamination of MISP events with data from previously processed STIX documents, affecting the integrity and accuracy of threat intelligence. This may lead to incorrect associations, misleading contextual information, or unrelated indicators being attributed to events. In scenarios where documents have different access controls or distribution scopes, it could result in limited disclosure of sensitive information from earlier documents. There is no direct impact on system availability or execution of arbitrary code.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid reusing the same parser instance for processing multiple independent STIX documents. Instead, instantiate a new parser for each document to prevent state contamination. Review application logic to ensure parser instances are not long-lived or reused across different documents.
CVE-2026-77761: CWE-459 Incomplete Cleanup in misp misp-stix
Description
A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into the MISP event generated from a subsequent document when the same parser instance is reused. Several STIX 1 and STIX 2 parser components maintained per-document state that was not completely cleared between conversions. In the STIX 2 parser, galaxy and galaxy-cluster information, including custom galaxy clusters, could survive a parser reset and subsequently be associated with objects from another bundle. The STIX 1 parsers were affected by the same underlying state-management issue. Depending on the parser type, retained information could include galaxies, references, passive DNS bookkeeping, package titles, dates, and timestamps. As a result, parsing a second STIX package with an already-used parser could produce a MISP event containing information that was present only in the previously processed package. For example, a generated event could inherit passive DNS records from an earlier document, reference unrelated galaxy information, combine titles from different packages, or use timestamps originating from another conversion. The issue primarily affects applications using the misp-stix API directly and reusing parser instances across independent STIX documents. Normal conversion entry points that instantiate a new parser for each file are not affected by this particular reuse scenario. An attacker able to influence documents processed by such a long-lived parser could potentially cause information from one conversion to contaminate a subsequent MISP event. This can affect the integrity of generated threat intelligence, resulting in incorrect associations, misleading contextual information, or unrelated indicators being attributed to an event. In environments where consecutive documents have different access controls or distribution scopes, the retained state could additionally result in limited disclosure of information from a previously processed document. Successful exploitation depends on the consuming application reusing the same parser instance and on the ordering of processed documents, which increases attack complexity. No direct availability impact or code execution is involved.
CVSS v4.0
Score 6.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in misp-stix arises from incomplete cleanup of parser state between processing STIX documents. Several parser components maintain per-document state that is not fully cleared upon parser reuse. In STIX 2 parsers, galaxy and galaxy-cluster data, including custom clusters, may persist and be incorrectly associated with new objects. STIX 1 parsers suffer from similar issues with retained galaxies, references, passive DNS data, titles, dates, and timestamps. This causes subsequent MISP events generated from reused parsers to contain data from previously processed documents, potentially misleading threat intelligence analysis or causing unauthorized information disclosure. The issue requires reuse of the same parser instance and specific document ordering, increasing exploitation complexity. There is no impact on availability or code execution.
Potential Impact
The vulnerability can cause contamination of MISP events with data from previously processed STIX documents, affecting the integrity and accuracy of threat intelligence. This may lead to incorrect associations, misleading contextual information, or unrelated indicators being attributed to events. In scenarios where documents have different access controls or distribution scopes, it could result in limited disclosure of sensitive information from earlier documents. There is no direct impact on system availability or execution of arbitrary code.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid reusing the same parser instance for processing multiple independent STIX documents. Instead, instantiate a new parser for each document to prevent state contamination. Review application logic to ensure parser instances are not long-lived or reused across different documents.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CIRCL
- Date Reserved
- 2026-08-21T10:11:49.766Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a8826fcacd9273b49fcf5f9
Added to database: 08/21/2026, 10:22:52 UTC
Last enriched: 08/21/2026, 10:37:20 UTC
Last updated: 08/21/2026, 11:03:50 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.