Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107335— Improper Handling of Highly Compressed Data in Malcolm

Quick assessment

Affected
CISA Malcolm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Malcolm 的上传处理流程(scripts/safe-extract.py)在解压容器格式压缩包(通过 libarchive 支持的 zip/tar/rar/7z 格式)时,会强制执行条目数量、嵌套深度以及总解压后字节数的限制。然而,当上传的文件是单流压缩格式(如 .gz、.bz2、.xz、.lzma、.lz),且非 .tar.* 类型的归档文件时,上述限制并未被应用。 任何被允许上传 PCAP 或日志文件身份的已认证用户,均可上传一个体积小但高度可压缩的文件(例如“gzip 炸弹”),该文件解压后会在磁盘上生

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 2

VendorProduct Version RangeStatus
CISA Malcolm ≤ 26.07.1 affected
26.08.0 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107335

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Improper Handling of Highly Compressed Data in Malcolm
Source: CVE Program / CVE List V5
Vulnerability Description
Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream compressed format (.gz, .bz2, .xz, .lzma, .lz) that isn't a .tar.*-style archive. Any authenticated user permitted to upload PCAP/log files can upload a small, highly compressible file (e.g. a gzip bomb) that decompresses to an effectively unbounded size on disk, exhausting the shared Docker volume used by OpenSearch, Logstash, Arkime, and Zeek, and disrupting the platform for all users.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对高度压缩数据的处理不恰当(数据放大攻击)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
CISA Malcolm 0 ~ 26.07.1 -

II. Public POCs for CVE-2026-107335

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107335

请登录查看更多情报信息。

Other References for CVE-2026-107335 (2)

Same Patch Batch · CISA · 2026-10-08 · 7 CVEs total

CVE-2026-107333 8.1 HIGH Incorrect Authorization in Malcolm
CVE-2026-107362 7.1 HIGH Server-Side Request Forgery in Malcolm
CVE-2026-107337 7.1 HIGH Cross-Site Request Forgery in Malcolm
CVE-2026-107336 6.5 MEDIUM Authentication Bypass by Spoofing in Malcolm
CVE-2026-107334 5.4 MEDIUM Incorrect Authorization in Malcolm
CVE-2026-107361 4.2 MEDIUM Authentication Bypass Using an Alternate Path or Channel in Malcolm

IV. Related Vulnerabilities

V. Comments for CVE-2026-107335

No comments yet


Leave a comment