CVE-2026-73160: cti-transmute Unauthenticated SSRF via Hostnames Resolving to Internal IP Addresses
Affected versions of cti-transmute contain an SSRF vulnerability in the /fetchmispevent and /mispsearchevents endpoints.
The URL validation routine checked whether a supplied hostname was itself an IP literal and rejected private, loopback, link-local, or reserved IPs. However, ordinary domain names were accepted without resolving them first. An attacker could therefore use a hostname whose DNS record pointed to an internal address and cause the cti-transmute server to issue requests into its internal network. The commit explicitly states that anonymous callers could make the server request the internal target and read the response.
The fix resolves hostnames using socket.getaddrinfo(), checks that every resolved address is globally routable, and additionally places @loginrequired on both affected MISP fetch/search routes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Add @login_required to the /fetch_misp_event route so anonymous callers cannot trigger SSRF requests.
cti-transmute /fetch_misp_event @login_required = enabled - Configuration
Add @login_required to the /misp_search_events route so anonymous callers cannot trigger SSRF requests.
cti-transmute /misp_search_events @login_required = enabled - Configuration
Update URL validation to resolve hostnames using socket.getaddrinfo(), then verify that every resolved address is globally routable (reject non-globally-routable targets).
cti-transmute hostname validation hostname resolution and address routability checks = use socket.getaddrinfo + require globally routable resolved addresses