A stored cross-site scripting (XSS) vulnerability in CTI Transmute's notification panel allowed JavaScript injection via unsanitized convert names rendered with innerHTML. The vulnerability was confined to a development branch and has been remediated by switching to DOM construction methods with textContent assignment.
CVE-2026-9137 is a medium-severity availability issue (CVSS 5.1) in a CSP report endpoint. The endpoint was intended to limit logged CSP reports to 1 KB, but the supplied source indicates it incorrectly allowed reports up to 1 MB before truncation. If the endpoint is reachable by untrusted clients, an attacker could drive excessive log volume and contribute to resource exhaustion or log flooding.
CVE-2026-9084 describes an authentication weakness in MISP’s OIDC plugin where an OIDC identity could be automatically linked to an existing local user account using the email claim if that account did not already have a stored sub value. In environments where the identity provider does not strongly enforce email ownership or is otherwise untrusted, a valid OIDC token asserting a victim’s email address co [truncated]
CVE-2026-44379 is a medium-severity vulnerability in MISP Collections that did not enforce RFC 4122 UUID validation on the uuid field prior to version 2.5.37. This oversight allowed users with the ability to create or modify Collection records to submit malformed UUID values, potentially causing integrity issues or unexpected behavior in code paths that assume Collection UUIDs are valid identifiers. The v [truncated]
CVE-2026-39962 is a high-severity LDAP injection vulnerability in the MISP (Malware Information Sharing Platform) open-source threat intelligence and sharing platform. The issue, fixed in version 2.5.36, arises from improper neutralization of special elements in an LDAP query within the ApacheAuthenticate.php file. This allows an attacker to manipulate the LDAP search filter by controlling the username va [truncated]