Scantide
Live local intelligence
2026-10-07 11:34 CEST · Intelligence refreshed (Europe/Stockholm)

Understand software risk,
with the evidence visible.

Search software, operating systems, packages, CVEs, KBs, campaigns, advisories, named operations or GHSAs and review correlated vulnerability, campaign, advisory, exploitation, update, affected-product and lifecycle intelligence in one place.

Latest synchronized CVE
CVSS 4.1 Published 2026-10-07 10:49 CEST
Vendor
Affected products
1 affected products/devices 1 operating system
General vulnerability query Recent High & critical CVEs

Query the vulnerability time window. Default 7 days; narrow to the last 24 hours or expand to 14 or 30 days when needed.

CVSS 6.9/10 Medium severity

CVE lookup — correlated security and lifecycle intelligence

· 8 sources correlated

Lower priority — confirm whether you are affected

STIX2 Parser Confusion and Mass Assignment Allow Unauthorized MISP Attribute Metadata Injection in misp-stix library

SeverityCVSS 6.9Medium · Remote / network
ExploitationNone reportedEPSS 0.5% chance in 30 days
Affected products8 products8 softwareEvidence8 sourcesindependent intelligence collections

Why this rating

  • It can be exploited remotely over the network.
  • Rated medium (CVSS 6.9); no exploitation is reported in current sources.

What to do

  1. Check your inventory against the 8 affected products — start with internet-facing systems.
Vendor
Affected products
,
,
,
,
+1 more

Affected products (examples)

Click to open the full list

What the vulnerability is

A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the STIX document itself. For STIX2, the presence of MISP-specific tool labels could cause a document to be classified as originating from MISP; similarly, STIX1 relied on the document title. These classification indicators are fully controlled …

Detailed evidence Everything below supports the summary above. Open only what you need.

Matched intelligence coverage 8 sources
EUVD Vulnrichment GHSA OSV EPSS CWE CVE Affected Products
Cross-source correlations 8 matched lanes

Direct intelligence-source relationships

Direct intelligence-source lanes: every lane below has direct evidence for

in that Scantide intelligence collection. Lanes share the CVE as their join key; their presence together does not imply that one source explicitly referenced another source's record.

Downstream affected vendors 1 vendors

Affected vendor/product relationships

These vendors are derived from affected product/device evidence tied to this CVE. This is intentionally separate from the direct intelligence-source lanes above: a vendor can have affected products without Scantide having a vendor-specific advisory or Microsoft KB record for the CVE.

1 affected vendors represented

Affected software, operating systems, hardware and devices 8

Deduplicated across Scantide's structured CVE, NVD applicability, CSAF, vendor advisory, campaign and downstream product evidence. Taxonomy IDs and evidence-only identifiers are excluded from the asset count. Counts represent relationships Scantide can currently prove, not the theoretical maximum downstream ecosystem.

8Software / applications
NVD/CVE catalog 1CISA Vulnrichment 4Osv 3
Software (8 — click to show all)
Vendor: MISP
Software Affected range: All listed or unspecified versions Product-associated Assertion
Primary: NVD/CVE cataloghigh confidence
Vendor: MISP
Software Affected range: through 2026.7.8 inclusive Product-associated Assertion
Primary: CISA Vulnrichment — structured affected recordhigh confidence
Vendor: Not identified in correlated evidence
Software Affected range: All listed or unspecified versions Product-associated Assertion
Primary: CISA Vulnrichmentmedium-high confidence
Vendor: Not identified in correlated evidence
Software Affected range: All listed or unspecified versions Product-associated Assertion
Primary: CISA Vulnrichmentmedium-high confidence
Vendor: Not identified in correlated evidence
Software Affected range: All listed or unspecified versions Product-associated Assertion
Primary: CISA Vulnrichmentmedium-high confidence
Vendor: Not identified in correlated evidence
Software Affected range: All listed or unspecified versions Product-associated Assertion
Primary: Osvmedium-high confidence
Vendor: Not identified in correlated evidence
Software Affected range: All listed or unspecified versions Product-associated Assertion
Primary: Osvmedium-high confidence
Vendor: Not identified in correlated evidence
Software Affected range: All listed or unspecified versions Product-associated Assertion
Primary: Osvmedium-high confidence
What each source says 3
European vulnerability intelligence: ENISA EUVD cross-reference: EUVD-2026-63850.
Exploit probability: Estimated exploitation probability 0.49% — percentile 40.3%.
Vulnerability summary: STIX2 Parser Confusion and Mass Assignment Allow Unauthorized MISP Attribute Metadata Injection in misp-stix library
GitHub package advisories 1
GHSA-PQPX-W6CX-7Q9C
GitHub Advisory
GHSA-PQPX-W6CX-7Q9C Published 2026-08-21T09:32:06Z Updated 2026-08-21T09:32:06Z

A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the STIX document itself. For STIX2, the presence of MISP-specific tool labels could cause a document to be classified as originating from MISP; similarly, STIX1 relied on the document title. These classification indicators are fully controlled by the STIX producer and therefore cannot constitute a trusted indication of the document's origin. The accompanying fix explicitly notes that the parser choice was previously based solely on labels or header titles that any producer could write, and introduces an explicit classification parameter allowing callers to override this detection. When STIX2 content was handled as an internal MISP export, attributes contained in an x-misp-object were converted by copying the comple…

GHSA-PQPX-W6CX-7Q9C
OSV advisories 1
CVE-2026-77710 Published 2026-08-21T08:54:01.414Z Updated 2026-10-03T11:45:51.292752974Z

A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the STIX document itself. For STIX2, the presence of MISP-specific tool labels could cause a document to be classified as originating from MISP; similarly, STIX1 relied on the document title. These classification indicators are fully controlled by the STIX producer and therefore cannot constitute a trusted indication of the document's origin. The accompanying fix explicitly notes that the parser choice was previously based solely on labels or header titles that any producer could write, and introduces an explicit classification parameter allowing callers to override this detection. When STIX2 content was handled as an internal MISP export, attributes contained in an x-misp-object were converted by copying the comple…

OSV-CONVERSIONOSV-OUTPUT
Related products
Evidence coverage

Correlated from multiple vulnerability, exploitation, advisory, package and affected-product intelligence collections.

Technical query coverage · 16 collections queried · 1 CVEs correlated
2026-10-07 11:34 CESTIntelligence refreshed
1unique CVEs queried and enriched
1unique CVEs correlated to this result
2unique advisories correlated
16intelligence collections queried
Affected-product scope: The product/device count is the deduplicated set Scantide can prove from its currently ingested structured records and advisory text. It is not a claim that only those products were affected; component vulnerabilities such as Log4Shell can have a much larger downstream ecosystem. Advisory and vendor references are kept clickable so additional downstream exposure can be followed to the authoritative source.
Coverage note: Scantide correlates multiple public and locally indexed intelligence sources, but no dataset or matching process is complete. Results may omit software, dependencies, affected versions or advisories, and related records do not by themselves prove that a specific installation is vulnerable. Confirm important findings against vendor guidance and the installed product and version.