Denial of Service Vulnerability in Malcolm Network Traffic Analysis Tool
CVE-2026-63133

6.5MEDIUM

Key Information:

Vendor

Cisagov

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-63133?

Malcolm, a network traffic analysis tool suite, has a vulnerability in its safe-extract.py script. Prior to version 26.07.0, the script does not impose limits on the number of entries, directory depth, total entries, or output size while extracting uploaded archives. This can lead to a situation where a maliciously crafted archive causes an excessive generation of filesystem objects, thereby exhausting inodes or filesystem metadata. As a consequence, this results in a denial of service for the processing pipeline and any services sharing the same mount point. The issue has been addressed in version 26.07.0.

Affected Version(s)

Malcolm < 26.07.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.