Entry-Count and Nested Depth Vulnerability in Malcolm's Upload Processing of Compressed Files
CVE-2026-19671

7.1HIGH

Key Information:

Vendor

Cisagov

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-19671?

Malcolm's upload-processing pipeline has a flaw where limits on entry counts, nesting depth, and total uncompressed bytes are not enforced for single-stream compressed formats. This allows authenticated users to upload small files that decompress into extremely large sizes, effectively consuming all available disk space in shared Docker volumes used by platforms like OpenSearch, Logstash, Arkime, and Zeek. As a consequence, this vulnerability can severely disrupt the operation of services reliant on these platforms.

Affected Version(s)

Malcolm 0 <= 26.07.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tinyb0y
.