Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-63133— Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS)

CVSS 6.5 · Medium EPSS 0.25% · P17

Possible ATT&CK Techniques 1AI

T1496 · Resource Hijacking

Affected Version Matrix 1

VendorProductVersion RangeStatus
cisagovMalcolm< 26.07.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-63133

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS)
Source: CVE Program / CVE List V5
Vulnerability Description
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries causes the filebeat processing container to create an unbounded number of filesystem objects, exhausting inodes or filesystem metadata and denying service to the processing pipeline and any service sharing the same mount. Version 26.07.0 fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5
Vulnerability Title
Cybersecurity and Infrastructure Security Agency Malcolm 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cybersecurity and Infrastructure Security Agency Malcolm是Cybersecurity and Infrastructure Security Agency组织的一款网络流量与日志分析平台。 Cybersecurity and Infrastructure Security Agency Malcolm 26.07.0之前版本存在资源管理错误漏洞,该漏洞源于safe-extract.py提取上传归档文件时未限制条目数量、目录深度、总条目数或输出大小,可
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
cisagovMalcolm < 26.07.0 -

II. Public POCs for CVE-2026-63133

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63133

登录查看更多情报信息。

Vendor Advisories for CVE-2026-63133 (1)

Vendor Pages for CVE-2026-63133 (1)

Same Patch Batch · cisagov · 2026-08-11 · 4 CVEs total

CVE-2026-556768.8 HIGHMalcolm vulnerable to RCE via unrestricted .php upload to the file-upload component
CVE-2026-631777.1 HIGHMalcolm Vulnerable to Authorization Bypass via URI Normalization Differential in Nginx Lua
CVE-2026-631345.4 MEDIUMMalcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Creation

IV. Related Vulnerabilities

V. Comments for CVE-2026-63133

No comments yet


Leave a comment