PYSEC-2026-2650
misp-modules has nsafe remote resource fetching in expansion
Details
An unsafe remote resource fetching vulnerability existed in MISP Modules expansion modules. The html_to_markdown module accepted arbitrary HTTP(S) URLs without sufficient validation, which could allow Server-Side Request Forgery against loopback, private, or link-local network resources. Additionally, the qrcode module disabled TLS certificate verification when retrieving remote images, exposing requests to potential man-in-the-middle interception or response tampering. The issue was fixed by validating URL schemes, blocking local and private address ranges, resolving hostnames before fetching, enforcing request timeouts, and re-enabling TLS certificate verification. As reported by Bilal Teke.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for misp-modules (pip). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/MISP/misp-modules/security/advisories/GHSA-fhq3-2gf3-8f3j[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-44363[ADVISORY]
- https://github.com/MISP/misp-modules/commit/01a522f2772fc31eeed379ccf23750c8a3d401db[WEB]
- https://github.com/MISP/misp-modules[PACKAGE]
- https://pypi.org/project/misp-modules[PACKAGE]
- https://github.com/advisories/GHSA-fhq3-2gf3-8f3j[ADVISORY]