CVE-2026-9137 PUBLISHED

CSP Report Endpoint Log Flooding via Incorrect Size Limit

Assigner: CIRCL
Reserved: 20.05.2026 Published: 20.05.2026 Updated: 20.05.2026

The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor misp
Product misp
Versions Default: unaffected
  • affected from 2.5.0 to 2.5.37 (incl.)

Credits

  • Seth Kraft finder

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE

Impacts

  • CAPEC-572 Artificially Inflate File Sizes