Back

MEDIUM

MISP: Authentication failure logging suppressed during Redis unavailability

Published Sep 15, 2026

Description

Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentication activity.

However, User->setupRedis() returns false when Redis cannot be reached. The vulnerable _shouldLog() logic only returned true when a Redis instance existed and no throttle key was present. Therefore, when Redis was unavailable, the function did not allow the log write at all, effectively silencing authentication-failure logging for the duration of the outage.

Version affected: ≤2.5.45

Affected products

Remediation

Vendor solution

The _shouldLog() method now explicitly checks whether the Redis connection is available before attempting to use it. If setupRedis() returns false, the method immediately returns true, causing every authentication-failure event to be logged. This converts the previous fail-closed behavior (silence on dependency failure) into a fail-open behavior for security logging (log everything when the throttle state is unavailable), ensuring that a Redis outage cannot be used to suppress the audit trail of failed authentication attempts.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CIRCL
Published Sep 15, 2026
Updated Sep 15, 2026
Reserved Sep 15, 2026
CISA Vulnrichment
Updated Sep 15, 2026
NVD
Status Deferred
Modified Sep 16, 2026
Red Hat
Severity n/a
Public date n/a