Security: OpenCTI-Platform/opencti
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
User-Controlled ReDoS in JSON Ingestion MapperGHSA-7g3x-wc2m-9h9x published
Aug 26, 2026 by fellowsebHigh -
Unauthenticated resource exhaustion via pre-auth body parsing in TAXII push endpointGHSA-6crf-vqpj-hvr4 published
Aug 26, 2026 by fellowsebHigh -
Broken Object Level Authorization (BOLA) for draft workspacesGHSA-8jgr-3543-vfvv published
Aug 26, 2026 by fellowsebHigh -
No rate limiting on authentication endpoint allows credential brute-forcingGHSA-74jw-q47r-q5pv published
Jul 28, 2026 by ludovicModerate -
Elasticsearch Painless Script Injection via GraphQL `script` filter operator allows authenticated user to exfiltrate data and cause DoSGHSA-qpp6-p693-rmm4 published
Jul 1, 2026 by fellowsebModerate -
XSS in the rendering of email-message observable body dataGHSA-rg6r-x26x-63vq published
Jun 1, 2026 by aHenryJardModerate -
Priviledge escalation and unauthenticated access using default adminGHSA-6vvv-vmfr-xhrx published
May 4, 2026 by aHenryJardCritical -
Authorization Bypass via `synchronized-upsert` HTTP Header InjectionGHSA-36fr-4m54-94mj published
Jun 26, 2026 by ludovicHigh -
Privilege escalation via graphQL API abusable by organization admins, due to incorrect ACL on userEdit relationAddGHSA-q537-qhj4-wcjx published
May 5, 2026 by aHenryJardHigh -
TAXII Public Collection Incorrect Authorization & Data LeakGHSA-wv3q-cfcg-crqq published
Jul 24, 2026 by SouadHadjiatModerate