Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/misp-stix

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-77761 is a parser state isolation vulnerability in the misp-stix component of MISP. It causes data from a previously processed STIX document to be retained and mixed into subsequent MISP events when the same parser instance is reused. This affects STIX 1 and STIX 2 parsers, leading to incorrect associations and potential limited information disclosure between events. The vulnerability requires reuse of parser instances and specific document ordering, increasing exploitation complexity. There is no impact on availability or code execution.

Join the discussion

CVE-2026-77755 is a denial-of-service vulnerability in misp-stix affecting versions up to and including 2026.7.8. It arises from improper handling of STIX 1 and STIX 2 documents during import, where sys.exit() calls cause process termination and no input size limits allow excessive memory and CPU consumption. Exploitation can terminate the importer process or degrade service availability.

Join the discussion

CVE-2026-77751 is a path traversal vulnerability in misp-stix affecting the handling of MISP object template names during STIX 2 import and export. The vulnerability allows crafted object names containing path traversal sequences to escape the intended template directory and load arbitrary definition.json files accessible to the process. This can lead to unintended disclosure of local data and modification of object metadata. The issue is mitigated by patches that enforce strict validation of object-template names, restricting them to safe characters and replacing invalid names with a generic placeholder.

Join the discussion

CVE-2026-77710 is a medium severity vulnerability in the misp-stix component of MISP that allows crafted STIX documents to manipulate security-sensitive attribute metadata during import. The vulnerability arises because the parser selection for STIX documents is based on untrusted metadata controlled by the document producer, enabling attackers to spoof MISP-origin indicators. This leads to improper input validation where attacker-supplied STIX bundles can inject unauthorized attribute properties such as distribution, sharing restrictions, and tags. This can cause information to be shared against organizational policies or influence downstream processing. The issue is addressed by introducing an explicit classification parameter and restricting accepted attribute fields via an allow-list.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:github/misp-stix
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses