Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-77761: CWE-459 Incomplete Cleanup in misp misp-stix

0
Medium
VulnerabilityCVE-2026-77761cvecve-2026-77761cwe-459
Published: 08/21/2026 (08/21/2026, 10:11:54 UTC)
Source: CVE Database V5
Vendor/Project: misp
Product: misp-stix

Description

A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into the MISP event generated from a subsequent document when the same parser instance is reused. Several STIX 1 and STIX 2 parser components maintained per-document state that was not completely cleared between conversions. In the STIX 2 parser, galaxy and galaxy-cluster information, including custom galaxy clusters, could survive a parser reset and subsequently be associated with objects from another bundle. The STIX 1 parsers were affected by the same underlying state-management issue. Depending on the parser type, retained information could include galaxies, references, passive DNS bookkeeping, package titles, dates, and timestamps. As a result, parsing a second STIX package with an already-used parser could produce a MISP event containing information that was present only in the previously processed package. For example, a generated event could inherit passive DNS records from an earlier document, reference unrelated galaxy information, combine titles from different packages, or use timestamps originating from another conversion. The issue primarily affects applications using the misp-stix API directly and reusing parser instances across independent STIX documents. Normal conversion entry points that instantiate a new parser for each file are not affected by this particular reuse scenario. An attacker able to influence documents processed by such a long-lived parser could potentially cause information from one conversion to contaminate a subsequent MISP event. This can affect the integrity of generated threat intelligence, resulting in incorrect associations, misleading contextual information, or unrelated indicators being attributed to an event. In environments where consecutive documents have different access controls or distribution scopes, the retained state could additionally result in limited disclosure of information from a previously processed document. Successful exploitation depends on the consuming application reusing the same parser instance and on the ordering of processed documents, which increases attack complexity. No direct availability impact or code execution is involved.

CVSS v4.0

Score 6.3medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
Low
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected software

GitHub Actionsmore threats →cve
misp-stix
pkg:github/misp-stix
Affected versions
<=2026.7.8

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/21/2026, 10:37:20 UTC

Technical Analysis

The vulnerability in misp-stix arises from incomplete cleanup of parser state between processing STIX documents. Several parser components maintain per-document state that is not fully cleared upon parser reuse. In STIX 2 parsers, galaxy and galaxy-cluster data, including custom clusters, may persist and be incorrectly associated with new objects. STIX 1 parsers suffer from similar issues with retained galaxies, references, passive DNS data, titles, dates, and timestamps. This causes subsequent MISP events generated from reused parsers to contain data from previously processed documents, potentially misleading threat intelligence analysis or causing unauthorized information disclosure. The issue requires reuse of the same parser instance and specific document ordering, increasing exploitation complexity. There is no impact on availability or code execution.

Potential Impact

The vulnerability can cause contamination of MISP events with data from previously processed STIX documents, affecting the integrity and accuracy of threat intelligence. This may lead to incorrect associations, misleading contextual information, or unrelated indicators being attributed to events. In scenarios where documents have different access controls or distribution scopes, it could result in limited disclosure of sensitive information from earlier documents. There is no direct impact on system availability or execution of arbitrary code.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid reusing the same parser instance for processing multiple independent STIX documents. Instead, instantiate a new parser for each document to prevent state contamination. Review application logic to ensure parser instances are not long-lived or reused across different documents.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CIRCL
Date Reserved
2026-08-21T10:11:49.766Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Threat ID: 6a8826fcacd9273b49fcf5f9

Added to database: 08/21/2026, 10:22:52 UTC

Last enriched: 08/21/2026, 10:37:20 UTC

Last updated: 08/21/2026, 11:03:50 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses