Denial of Service Vulnerability in Malcolm by CISA Government
CVE-2026-107335

6.5MEDIUM

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107335?

Malcolm's upload-processing pipeline has a significant vulnerability that does not enforce its extraction limits when handling single-stream compressed formats. Authenticated users can exploit this weakness by uploading small, highly compressible files like gzip bombs. When decompressed, these files can occupy an unbounded amount of disk space, which can exhaust the shared Docker volume utilized by Malcolm's components like OpenSearch, Logstash, Arkime, and Zeek, thereby causing a disruption in service for all users.

Affected Version(s)

Malcolm 0 <= 26.07.1

Malcolm 26.08.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seth Grover
.