Entry-Count and Nested Depth Vulnerability in Malcolm's Upload Processing of Compressed Files
CVE-2026-19671
7.1HIGH
What is CVE-2026-19671?
Malcolm's upload-processing pipeline has a flaw where limits on entry counts, nesting depth, and total uncompressed bytes are not enforced for single-stream compressed formats. This allows authenticated users to upload small files that decompress into extremely large sizes, effectively consuming all available disk space in shared Docker volumes used by platforms like OpenSearch, Logstash, Arkime, and Zeek. As a consequence, this vulnerability can severely disrupt the operation of services reliant on these platforms.
Affected Version(s)
Malcolm 0 <= 26.07.1
