← Back to all sparks
M

MISP

INFRA · APIS
Velocity6.3

Open-source threat intelligence and information sharing platform

MISP 2.5.46 delivers a 50× sightings query speedup and systematic SSRF closure — serious infrastructure work.

threat-intelligencecybersecurityperformancesecurity-hardeningopen-source
Current state
MISP is on a high-velocity cycle, shipping security audits and performance overhauls in parallel with the Overmind (Bootstrap 5) UI migration. Version 2.5.46 introduced a UrlEgressValidator providing a shared policy for all outbound URL requests and closing multiple SSRF vectors, while cutting sightings-retrieval query counts from 10,661 to 6 (a 50× reduction) and accelerating event report counts by 19–35×. The knowledge bases — misp-galaxy and misp-warninglists — are maintained as continuously updated datasets tracking ATT&CK changes and scanner infrastructure.
Where it's heading
Three parallel tracks define MISP's near-term direction: systematic security hardening (the 74-controller audit from 2.5.42 and the UrlEgressValidator framework in 2.5.46 signal structured review, not one-off patches), performance at scale (query-level optimizations targeting high-volume REST API and export workloads), and Overmind as the long-term UI replacement. Collection sync between instances, added in 2.5.43, opens a federation angle that matters for multi-tenant deployments and national MISP communities.
Prediction
The next release will extend the UrlEgressValidator to remaining outbound paths not yet covered, and push more Overmind screens to production-ready status. Collection sync improvements are probable as early adopters stress-test cross-instance federation at scale.

Recent moves

  1. 5d ago

    MISP 2.5.46 released - security hardening, major performance gains, knowledge-base updates and Overmind moving forward

    ⚡ SPARK

    The headline moves in 2.5.46 are the 50× sightings query reduction (8.1s → 0.15s, 10,661 queries → 6) and the new UrlEgressValidator, which begins systematic closure of MISP's outbound SSRF surface — two changes that together represent a step-change in performance and security posture for large, multi-user instances.

    View source ↗
  2. 21d ago

    MISP v2.5.45 released - Overmind Everywhere, LDAP Reworked, Security Hardened and Many Fixes

    A six-week cycle advancing the Overmind UI migration into server settings, workflow editors, and feed management, alongside a full LDAP authentication revamp with group-based role mapping and CI-backed test coverage — real infrastructure work for enterprise and government deployments.

    View source ↗
  3. 2mo ago

    MISP v2.5.43 released

    Collection synchronisation between MISP instances — pull and push directions, feature negotiation for backward compatibility, and paginated negotiation for memory efficiency — extends the federation model meaningfully; env-var settings unlock container and IaC deployments.

    View source ↗
  4. 2mo ago

    MISP v2.5.44 released

    Hotfix release addressing a pull-synchronisation failure on events without tags, plus continued Overmind Bootstrap 5 view additions — routine maintenance following the 2.5.43 feature cycle.

    View source ↗
  5. 2mo ago

    MISP 2.5.42 - scorching hot weather release

    ⚡ SPARK

    The 2.5.42 security audit closed two RCE vectors via strict config-path validation and systematically swept 74 controllers for mass-assignment and broken-access-control vulnerabilities — a codebase-wide hardening pass unusual in scope for open-source threat intelligence infrastructure.

    View source ↗
  6. 3mo ago

    MISP 2.5.41 - heatwave edition

    2.5.41 adds mass event tagging, galaxy cluster ACL enforcement on dashboards, and a sync optimization replacing full tag-list fetches with fingerprints — incremental work that moves MISP's scale ceiling upward without changing the product surface.

    View source ↗