Vulnerability in Log-Processing Component of HTTP Client Library by Vendor
CVE-2026-90455

6.3MEDIUM

Key Information:

Vendor

Cisa

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-90455?

An earlier update intended to mitigate known vulnerabilities in a bundled HTTP client library was reverted, inadvertently bringing back a version known to contain security flaws. This vulnerability impacts the log-processing component that utilizes this library. While the component initializes the library by making a request to a trusted vendor URL, it does not process external input through the library, which restricts the potential for exploitation. However, the presence of the vulnerable library version suggests a need for increased vigilance and ongoing monitoring for any emerging threats.

Affected Version(s)

Malcolm 0

Malcolm v26.06.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.