A high-severity server-side request forgery flaw tracked as CVE-2026-73160 was disclosed in MISP's cti-transmute component, affecting the /fetch_misp_event and /misp_search_events endpoints. The issue stemmed from validation that blocked direct private or reserved IP literals but still accepted ordinary hostnames without resolving them first, allowing an unauthenticated attacker to supply a domain that resolved to an internal address and force the server to send requests into its internal network and return the responses. The vulnerability is rated CVSS 4.0 8.7 (High) and is mapped to CWE-918.
MISP addressed the flaw by updating URL validation to resolve hostnames with socket.getaddrinfo() and reject targets if any resolved address is not globally routable, covering private, loopback, link-local, and reserved destinations. The fix also added login protection to both affected routes, reducing exposure of functionality that queries external MISP instances. Project notes indicate some residual DNS rebinding or post-validation DNS swap risk may remain for limited probing, but response-body exposure is constrained because valid TLS certificates are required for the hostname and redirects are not followed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-73160 was published for an unauthenticated SSRF vulnerability in MISP's cti-transmute affecting versions up to and including 1.4.0. The issue allowed attackers to supply hostnames resolving to internal addresses via the /fetch_misp_event and /misp_search_events endpoints, and it was rated CVSS 4.0 8.7 High.
A code change in MISP's cti-transmute updated URL validation to resolve hostnames and reject any non-globally-routable resolved addresses, mitigating SSRF through DNS-resolved internal IPs. The same patch also added @login_required to the /fetch_misp_event and /misp_search_events routes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.