CVE-2026-94383

CVE-2026-94383 published: The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path components and a check for empty or dot values. A site administrator c...

View full NVD advisory → ← Back to CVE watch