โ† Back to Feed

CISA Malcolm

CVE-2026-55676CVE-2026-63133CVE-2026-63134CVE-2026-63177CVE-2026-19670CVE-2026-19671

August 18, 2026 ยท CISA (US-CERT) ยท Severity: CRITICAL

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code. The following versions of CISA Malcolm are affected: Malcolm <26. 06. 1 (CVE-2026-55676) Malcolm <26. 07. 0 (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177) Malcolm <=26. 07. 1 (CVE-2026-19670, CVE-2026-19671) CVSS Vendor Equipment Vulnerabilities v3 8. 8 CISA CISA Malcolm Allocation of Resources Without Limits or Throttling, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangerous Type, Incorrect Authorization, Improper Handling of Highly Compressed Data (Data Amplification) Background Critical Infrastructure Sectors: Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-63133 Malcolm is a network traffic analysis tool suite. Prior to version 26. 07. 0, safe-extract.py extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries causes the filebeat processing container to create an unbounded number of filesystem objects, exhausting inodes or filesystem metadata and denying service to the processing pipeline and any service sharing the same mount. Version 26. 07. 0 fixes the issue. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm: <26. 07. 0 Product Status:known_affected Remediations Vendor fixMalcolm version 26. 07. 0 addresses these issues. For more information, see https://github.com/cisagov/Malcolm/pull/1043. (CVE-2026-63133, CVE-2026-63134, CVE-2026-63177)https://github.com/cisagov/Malcolm/pull/1043 Relevant CWE: CWE-770 Allocation of Resources Without Limits or Throttling Metrics CVSS Version Base Score Base Severity Vector... ๐Ÿ“Œ **Analyst Note:** These six CVEs in CISA's own Malcolm tool highlight the complexity of securing network analysis pipelines. Multiple archive extraction flaws (path traversal, decompression bombs, resource exhaustion) reflect common weaknesses in file-processing code. Organizations using Malcolm should upgrade to version 26. 07. 0 or later and audit any custom archive extraction logic for similar vulnerabilities.

Key Takeaways

  • CISA Malcolm versions before 26. 07. 0 contain six vulnerabilities including path traversal, arbitrary file upload, and resource exhaustion flaws.
  • CVE-2026-63133 allows denial-of-service via malicious archives that exhaust filesystem inodes in the filebeat processing container.
  • CVE-2026-63134 enables path traversal through directory entries with ../ sequences escaping the intended extraction directory.
  • CVE-2026-19670 and CVE-2026-19671 affect Malcolm up to version 26. 07. 1 with improper authorization and decompression amplification issues.
โ˜• Buy a Coffee