Skip to main content
EPSS 0.6%top 53%

CVE-2026-77761: CWE-459 Incomplete Cleanup in misp misp-stix

0
Medium
Published: 08/21/2026 (08/21/2026, 10:11:54 UTC)
Source: CVE Database V5
Vendor/Project: misp
Product: misp-stix

Description

CVE-2026-77761 is a parser state isolation vulnerability in the misp-stix component of MISP. It causes data from a previously processed STIX document to be retained and mixed into subsequent MISP events when the same parser instance is reused. This affects STIX 1 and STIX 2 parsers, leading to incorrect associations and potential limited information disclosure between events. The vulnerability requires reuse of parser instances and specific document ordering, increasing exploitation complexity. There is no impact on availability or code execution.

CVSS v4.0

Score 6.3medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
Low
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected software

misp

misp-stix

Affected versions
>=0 <=2026.7.8
GitHub Actionsmore threats →cve
misp-stix
pkg:github/misp-stix
Affected versions
>=0 <=2026.7.8

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 03:04:22 UTC

Technical Analysis

The vulnerability in misp-stix arises from incomplete cleanup of parser state between processing STIX documents. Several STIX 1 and STIX 2 parser components maintain per-document state that is not fully cleared on reuse. In STIX 2, galaxy and galaxy-cluster data, including custom clusters, can persist after a parser reset and be incorrectly associated with objects from a different bundle. STIX 1 parsers similarly retain galaxies, references, passive DNS data, package titles, dates, and timestamps. This causes subsequent MISP events generated by the reused parser to contain data from previously processed documents, potentially contaminating threat intelligence with unrelated or misleading information. The issue primarily affects applications that reuse parser instances via the misp-stix API rather than those that instantiate a new parser per document. Exploitation requires control over the documents processed by a long-lived parser and depends on document ordering.

Potential Impact

The vulnerability can compromise the integrity of threat intelligence by causing MISP events to include data from unrelated STIX documents. This may lead to incorrect associations, misleading contextual information, or unrelated indicators being attributed to events. In environments with different access controls or distribution scopes for consecutive documents, there is a risk of limited disclosure of information from previously processed documents. There is no impact on system availability or code execution. Exploitation complexity is increased due to the need for parser reuse and document ordering.

Mitigation Recommendations

No official patch or fix is currently documented. The vulnerability primarily affects applications that reuse the same parser instance for multiple STIX documents. Mitigation involves ensuring that a new parser instance is created for each STIX document processed, avoiding reuse of parser instances. Users should review their use of the misp-stix API to confirm that parser instances are not reused across independent documents. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CIRCL
Date Reserved
2026-08-21T10:11:49.766Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a8826fcacd9273b49fcf5f9

Added to database: 08/21/2026, 10:22:52 UTC

Last enriched: 09/11/2026, 03:04:22 UTC

Last updated: 10/05/2026, 06:48:18 UTC

Views: 85

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses