GHSA-fhq3-2gf3-8f3j

Suggest an improvement
Source
https://github.com/advisories/GHSA-fhq3-2gf3-8f3j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fhq3-2gf3-8f3j/GHSA-fhq3-2gf3-8f3j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fhq3-2gf3-8f3j
Aliases
  • CVE-2026-44363
Published
2026-05-06T22:31:03Z
Modified
2026-05-14T20:49:45.105782Z
Severity
  • 5.8 (Medium) CVSS_V4 - CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H CVSS Calculator
Summary
misp-modules has nsafe remote resource fetching in expansion
Details

An unsafe remote resource fetching vulnerability existed in MISP Modules expansion modules. The htmltomarkdown module accepted arbitrary HTTP(S) URLs without sufficient validation, which could allow Server-Side Request Forgery against loopback, private, or link-local network resources. Additionally, the qrcode module disabled TLS certificate verification when retrieving remote images, exposing requests to potential man-in-the-middle interception or response tampering. The issue was fixed by validating URL schemes, blocking local and private address ranges, resolving hostnames before fetching, enforcing request timeouts, and re-enabling TLS certificate verification. As reported by Bilal Teke.

Database specific
{
    "github_reviewed_at": "2026-05-06T22:31:03Z",
    "nvd_published_at": "2026-05-13T20:16:23Z",
    "cwe_ids": [
        "CWE-295",
        "CWE-918"
    ],
    "severity": "MODERATE",
    "github_reviewed": true
}
References

Affected packages

PyPI / misp-modules

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.0.7

Affected versions

2.*
2.4.196
2.4.197
2.4.198
2.4.199
2.4.200
2.4.201
3.*
3.0.0
3.0.1
3.0.2
3.0.4
3.0.5
3.0.6
3.0.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-fhq3-2gf3-8f3j/GHSA-fhq3-2gf3-8f3j.json"