2026-08-23NOTABLEThe library that converts STIX into MISP decided a document was trustworthy using markers the sender controls, and the fix exists only as commits
misp-stix cross-document parser state contamination (CVSS 4.0 6.3), reused parser instances retained galaxy data, references, titles and timestamps across conversions, so one document's content can appear in the event generated from the next. Last affected 2026.7.8; fixed by commits only.
cve · CVE-2026-77761 single-source
Coverage
1
first 2026-08-23 → last 2026-08-23
Latest activity
2026-08-23
The library that converts STIX into MISP decided a document was trustworthy using markers the sender…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector · regions: europe
Sources cited
6
2 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-77761, newest first. Check the date before acting on an older one.
- Audit any misp-stix automation that reuses one parser instance across several documents (batch import scripts are the affected pattern) and switch it to a fresh parser per document; per-file CLI invocations are unaffected.2026-08-23CVE-2026-77710 +2
Defender insights
What each entry about CVE-2026-77761 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (2 across 1 tactic)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ImpactEndpoint Denial of Service · Data Manipulation: Stored Data Manipulation
Impact TA0040
T1499Endpoint Denial of Service×1
Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users. Endpoint DoS can be performed by exhausting the system resources those services are hosted on or exploiting the system to cause a persistent crash condition. Example services include websites, email services, DNS, and web-based applications. Adversaries have been observed conducting DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.
Evidence: 2026-08-23/misp-stix-import-trust-boundary-dos-parser-state · ATT&CK page ↗
T1565.001Data Manipulation: Stored Data Manipulation×1
Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating stored data, adversaries may attempt to affect a business process, organizational understanding, and decision making.
Evidence: 2026-08-23/misp-stix-import-trust-boundary-dos-parser-state · ATT&CK page ↗
Entries about misp-stix cross-document parser state contamination (CVSS 4.0 6.3), reused parser instances retained galaxy data, references, titles and timestamps across conversions, so one document's content can appear in the event generated from the next. Last affected 2026.7.8; fixed by commits only. (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- MISP misp-stix×1
- misp-stix denial of service (CVSS 4.0 8.7), parse failures called sys.exit(), raising SystemExit past callers' exception handlers, so one malformed STIX document terminates a long-running importer; no size limit was applied before parsing. Last affected 2026.7.8; fixed by commits only.×1
- misp-stix STIX-import trust-boundary flaw (CVSS 4.0 6.9); the importer decided whether a document was a trusted internal MISP export from markers the producer controls, then copied a whole attribute dictionary onto imported attributes, letting a crafted bundle set distribution, sharing_group_id and tags. Last affected 2026.7.8; fixed by commits only, no tagged release.×1
Where this entity is cited
Source distribution
- euvd.enisa.europa.eu3 (50%)
- osv.dev3 (50%)
External references
All cited sources (6)
- osv.devprimaryMISP Project advisory (via OSV.dev)https://osv.dev/vulnerability/CVE-2026-77710
- osv.devprimaryMISP Project advisory (via OSV.dev)https://osv.dev/vulnerability/CVE-2026-77755
- osv.devprimaryMISP Project advisory (via OSV.dev)https://osv.dev/vulnerability/CVE-2026-77761
- euvd.enisa.europa.euENISA EU Vulnerability Databasehttps://euvd.enisa.europa.eu/vulnerability/EUVD-2026-63850
- euvd.enisa.europa.euENISA EU Vulnerability Databasehttps://euvd.enisa.europa.eu/vulnerability/EUVD-2026-63881
- euvd.enisa.europa.euENISA EU Vulnerability Databasehttps://euvd.enisa.europa.eu/vulnerability/EUVD-2026-63883