CVE-2026-73160
Last modified
CVE-2026-73160 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation routine checked whether a supplied hostname was itself an IP literal and rejected private, loopback, link-local, or reserved IPs. However, ordinary domain names were accepted without resolving them first.
Description
Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation routine checked whether a supplied hostname was itself an IP literal and rejected private, loopback, link-local, or reserved IPs. However, ordinary domain names were accepted without resolving them first. An attacker could therefore use a hostname whose DNS record pointed to an internal address and cause the cti-transmute server to issue requests into its internal network. The commit explicitly states that anonymous callers could make the server request the internal target and read the response. The fix resolves hostnames using socket.getaddrinfo(), checks that every resolved address is globally routable, and additionally places @login_required on both affected MISP fetch/search routes.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MISP | cti-transmute | <= 1.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-73160?
How severe is CVE-2026-73160?
How do I fix CVE-2026-73160?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73155Affected versions of cti-transmute allow authenticated users…5.3
- CVE-2026-73156Affected versions of cti-transmute fail to HTML-escape attac…5.3
- CVE-2026-73157Affected versions of cti-transmute render data obtained from…2.3
- CVE-2026-73158Affected versions of cti-transmute insufficiently validate s…5.1
- CVE-2026-73159Affected versions of cti-transmute allow a tag's icon value …5.1
- CVE-2026-7316A vulnerability has been found in eiliyaabedini aider-mcp up…7.3
- CVE-2026-73161Affected versions of cti-transmute improperly handle convers…5.1
- CVE-2026-73162Affected versions of MISP cti-transmute expose several state…5.3
- CVE-2026-7317A vulnerability was found in Grav CMS up to 1.7.49.5/2.0.0-b…5
- CVE-2026-7318A vulnerability was detected in elie mcp-project 0.1.0. The …5.9
- CVE-2026-7319A flaw has been found in elinsky execution-system-mcp 0.1.0.…7.3
- CVE-2026-7320Information disclosure due to incorrect boundary conditions …7.5
Are you affected by CVE-2026-73160?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
