All 3 CVE vulnerabilities found in malcontent, with AI-generated Chinese analysis, references, and POCs.
Vendor: chainguard-dev
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-28407 | malcontent's nested archive extraction failure can drop content from scan inputs CWE-703 | 8.2 | - | 2026-02-27 |
| CVE-2026-24846 | malcontent's archive extraction could write outside extraction directory CWE-22 | 5.5 | Medium | 2026-01-29 |
| CVE-2026-24845 | malcontent's OCI image scanning could expose registry credentials CWE-522 | 6.5 | Medium | 2026-01-29 |
All 3 known CVE vulnerabilities affecting malcontent with full Chinese analysis, references, and POCs where available.