Retour à la veille

CVE-2026-104906

Publié : 2 octobre 2026
Modifié : 2 octobre 2026
Lien officiel NVD

Description détaillée

MISP contains a cross-site scripting (XSS) vulnerability in the TAXII object viewer. When displaying a remote TAXII object, the JSON content of string properties was rendered directly into an HTML pre block without HTML-encoding. An attacker who can control or influence the content of a TAXII object (e.g., by publishing a malicious object to a TAXII server that the victim's MISP instance subscribes to) can inject arbitrary HTML or JavaScript that executes in the context of the victim's MISP session. Preconditions: - The victim must be an authenticated MISP user with access to the TAXII object viewer. - The victim must open or view the crafted TAXII object. Impact: - Execution of arbitrary JavaScript in the victim's browser within the MISP application context. - Potential theft of session tokens, API keys, or other sensitive data accessible from the MISP interface. - Potential for performing actions on behalf of the authenticated user. Affected versions: <2.5.48.

Références et Patchs

Dernières Vulnérabilités

CVE-2026-64818

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

VOIR DÉTAILS

CVE-2026-59265

A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences dialog. This prevents the attack. If this is not possible, or as an extra precaution, you can avoid opening open untrusted files entirely. Once 4.1.17 is released, upgrade to that version to fix the issue.

VOIR DÉTAILS

CVE-2026-104861

probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /<[-_.:a-zA-Z0-9][^>]*>/, which repeatedly scans to the end of input when attacker-controlled data contains many less-than characters without a closing greater-than character. The synchronous parser converts and scans the full supplied buffer without an input cap, while the streaming parser reparses the complete accumulated SVG prefix for every received chunk. The probe.sync(), probe(stream), and probe(url) entry points can therefore block the Node.js event loop at full CPU, and attacker-controlled chunking can amplify the streaming cost. This issue is fixed in version 7.4.0.

VOIR DÉTAILS