← Back to all sparks
M

MISP

INFRA · APIS
Velocity6.3

Open-source threat intelligence and information sharing platform

MISP extends instance-to-instance sync to collections while a security-hardening program runs underneath

threat-intelligencefederationsecurity-hardeningui-migrationstix-taxiisync
Current state
MISP is shipping on a roughly two-week cadence, and three tracks run through every release. The first is federation: 2.5.43 added collection synchronisation between instances in both pull and push directions, with per-server toggles and feature negotiation. The second is a sustained security program — 2.5.40, 2.5.41 and 2.5.42 are all substantially security releases, with 2.5.42 alone closing two RCE vectors and a mass-assignment sweep across a 74-controller review. The third is the Overmind UI migration to Bootstrap 5, which lands a batch of converted views in nearly every release.
Where it's heading
The security work reads as a deliberate audit rather than incident response — the fixes are systematic (mass-assignment and broken-access-control across the controller layer, OIDC hardening, ACL enforcement on cluster search) and credited to named external researchers across four consecutive releases. Alongside it, the interop surface keeps widening: TAXII 2 conformance and scheduled push, STIX moved onto the upstream misp-stix library, and now collection sync. The Overmind migration is the slow constant, converting the UI tab by tab rather than in one cutover.
Prediction
The Overmind migration and the Pivotick pivot explorer are both mid-rollout, so the next releases should continue converting views and fill out Pivotick rather than open a new track. Given the pattern of the last four releases, expect further externally-reported security fixes to ship alongside them.

Recent moves

  1. 18d ago

    Collections now sync between MISP instances, plus Pivotick pivot explorer

    ⚡ SPARK

    Collections become synchronisable between MISP instances in both directions, with per-server pull and push toggles and feature negotiation. Sharing between instances is MISP's core function, so extending it to a new object type moves the federation model rather than the UI on top of it. The release also carries the first cut of the Pivotick pivot explorer and environment-variable-based settings.

    View source ↗
  2. 18d ago

    Hotfix for pull sync failing on untagged events

    A hotfix on top of 2.5.43 for a pull-synchronisation failure when events carried no tags, caused by local-versus-remote tag comparison on internal servers. It ships with another large batch of Bootstrap 5 views for the Overmind theme, continuing the migration that runs through every recent release.

    View source ↗
  3. 1mo ago

    Two RCE fixes and a 74-controller access-control sweep, plus TAXII scheduled push

    Primarily a security hardening release, closing two RCE vectors, an authentication-hardening issue, and a broad sweep of mass-assignment and broken-access-control fixes drawn from a review of 74 controllers. It also adds TAXII scheduled push and another Overmind iteration, so the interop and UI tracks continue underneath the security work.

    View source ↗
  4. 1mo ago

    Galaxy cluster mass-assignment, OIDC redirect loop and dashboard ACL fixes

    A security release fixing a mass-assignment in galaxy cluster relations where a POSTed id could turn an add into an overwrite, an OIDC redirect loop for users disabled on the MISP side, and ACL enforcement on dashboard cluster search. Part of the run of externally-reported fixes that spans 2.5.40 through 2.5.42.

    View source ↗
  5. 1mo ago

    Security release resolving externally disclosed vulnerabilities

    A security-focused release resolving a batch of vulnerabilities disclosed by three external researchers, with multi-tenant and multi-homed deployments called out as the ones most exposed. Bug fixes and data-library refreshes round it out; no new capability surface.

    View source ↗
  6. 1mo ago

    MISP 2.5.39: New Dashboard Experience, Stronger STIX, Sharper Analyst Workflows

    A broad release across the new dashboard experience, analyst-focused widgets, and STIX interoperability, with security fixes attached. It marks the point where the dashboard rework became substantial enough that instances relying on dashboards, templates, TAXII or LDAP mixed auth were told to upgrade specifically.

    View source ↗