CVE-2026-69079
8.7MISP · cti-transmute
CTI-Transmute is vulnerable to an uncontrolled resource consumption attack at the unauthenticated activity_timeline endpoint, which could lead to a denial of service.
Executive summary
An unauthenticated resource consumption vulnerability in the MISP cti-transmute activity_timeline endpoint poses a risk of service disruption through excessive resource exhaustion.
Vulnerability
The application lacks necessary limits or throttling on the /activity_timeline endpoint, allowing an unauthenticated attacker to exhaust system resources. This is categorized as a resource consumption vulnerability under CWE-770.
Business impact
Exploitation of this vulnerability could cause the application to become unresponsive, leading to significant system downtime and denial of service for legitimate users. With a CVSS score of 8.7, the impact on business continuity is severe, especially for organizations that rely on the availability of the CTI-Transmute service.
Remediation
Immediate Action: Apply the latest security updates provided by the vendor to implement proper rate limiting and resource controls.
Proactive Monitoring: Monitor system resource usage, specifically CPU and memory consumption, for spikes related to requests targeting the activity_timeline endpoint.
Compensating Controls: Use a rate-limiting policy at the load balancer or reverse proxy level to restrict the number of requests per IP address to the affected endpoint.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Service availability is a critical component of security. It is highly recommended that administrators apply available patches to enforce rate limiting and prevent the potential for denial of service attacks against the application.
More MISP CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section
- Fix documented per CVE record