Vulnerability in Log-Processing Component of HTTP Client Library by Vendor
CVE-2026-90455
6.3MEDIUM
What is CVE-2026-90455?
An earlier update intended to mitigate known vulnerabilities in a bundled HTTP client library was reverted, inadvertently bringing back a version known to contain security flaws. This vulnerability impacts the log-processing component that utilizes this library. While the component initializes the library by making a request to a trusted vendor URL, it does not process external input through the library, which restricts the potential for exploitation. However, the presence of the vulnerable library version suggests a need for increased vigilance and ongoing monitoring for any emerging threats.
Affected Version(s)
Malcolm 0
Malcolm v26.06.0
