GHSA-fjjq-85mx-vg3vMedium

MISP contains a race condition in the email-based one-time password (OTP) login flow. When two...

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect.

Preconditions:

  • The target MISP instance has email OTP login enabled.

  • The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering).

  • The attacker can issue two HTTP POST requests in close temporal proximity.

Impact:

  • The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions.

  • This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted.

Affected versions: <2.5.48

🔗 References (3)