Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to version v26.08.0
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream compressed format (.gz, .bz2, .xz, .lzma, .lz) that isn't a .tar.*-style archive. Any authenticated user permitted to upload PCAP/log files can upload a small, highly compressible file (e.g. a gzip bomb) that decompresses to an effectively unbounded size on disk, exhausting the shared Docker volume used by OpenSearch, Logstash, Arkime, and Zeek, and disrupting the platform for all users. | |
| Title | Improper Handling of Highly Compressed Data in Malcolm | |
| Weaknesses | CWE-409 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-10-08T19:05:41.651Z
Reserved: 2026-10-07T18:31:15.966Z
Link: CVE-2026-107335
No data.
Status : Received
Published: 2026-10-08T18:17:19.970
Modified: 2026-10-08T20:17:32.407
Link: CVE-2026-107335
No data.
OpenCVE Enrichment
Updated: 2026-10-08T18:30:07Z
-
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)