MISP 2.5.42 patches two RCE flaws
MISP 2.5.42 closes two remote code execution vulnerabilities and fixes 13 mass-assignment issues across 74 controllers in a comprehensive security audit.
MISP has released version 2.5.42, a security-focused update that addresses critical vulnerabilities discovered through a systematic codebase-wide audit. The release patches two remote code execution vectors: one via arbitrary rdkafka configuration file paths and another through arbitrary ndjson log paths. Both RCE vulnerabilities previously required a compromised site-admin account for exploitation but are now fully remediated through strict path validation and CLI-only configuration restrictions.
The security audit covered 74 controllers and resulted in 13 mass-assignment fix commits and multiple broken-access-control remediations. Seven specific IDOR (Insecure Direct Object Reference) issues were identified and fixed across EventReports, SharingGroups, CollectionElements, TemplateElements, and DecayingModel subsystems. Additionally, the release hardens Azure AD authentication and includes 24 commits advancing the new Overmind UI.
MISP maintainers strongly recommend immediate upgrading given the severity of the patched vulnerabilities. The release also introduces new TAXII scheduled-push capabilities with proxy support, updates to default feeds including SiberKapan, and refreshed data libraries for galaxies, objects, taxonomies, and warning lists.
Mentioned in this report
Source reporting: https://www.misp-project.org/2026/06/22/misp.2.5.42.release.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free