Cisagov Malcolm vulnerabilities
6 known vulnerabilities affecting cisagov/malcolm.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2026-55676P2HIGHCVSS 8.8fixed in 26.06.12026-08-11
CVE-2026-55676 [HIGH] CWE-434 CVE-2026-55676: Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) a
Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (`file-upload/php/config.php:16`), so the
nvd
CVE-2026-63177P3HIGHCVSS 7.1fixed in 26.07.02026-08-11
CVE-2026-63177 [HIGH] CWE-863 CVE-2026-63177: Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access contro
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can prepend a traversal segment (for example `/x/../uplo
nvd
CVE-2026-19671P3MEDIUMCVSS 6.5≤ 26.07.12026-08-18
CVE-2026-19671 [MEDIUM] CWE-409 CVE-2026-19671: Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth,
Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream compressed format (.gz, .bz2, .xz, .lzma, .lz) that isn't a .tar.*-style a
nvd
CVE-2026-63133P3MEDIUMCVSS 6.5fixed in 26.07.02026-08-11
CVE-2026-63133 [MEDIUM] CWE-770 CVE-2026-63133: Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extrac
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries causes the filebeat processing container to create an unbounded number
nvd
CVE-2026-19670P4MEDIUMCVSS 5.4≤ 26.07.12026-08-18
CVE-2026-19670 [MEDIUM] CWE-863 CVE-2026-19670: Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may
Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /auth, /admin_login, /arkime/api/esadmin, NetBox, upload endpoints) by pattern-matching the raw, percent-encoded request URI. Nginx itself, however, selects which location block actually serves the request
nvd
CVE-2026-63134P4MEDIUMCVSS 5.4fixed in 26.07.02026-08-11
CVE-2026-63134 [MEDIUM] CWE-22 CVE-2026-63134: Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protec
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest, entry.pathname))` that has no traversal protection. An uploaded malicious archive containing a directory entry with a `../` sequ
nvd