Please see the DHS Vulnerability Disclosure Policy for details about how we handle vulnerability disclosure.
Security: cisagov/Malcolm
Security
SECURITY.md
-
Percent-Encoded Request Paths Bypass Malcolm's nginx RBACGHSA-jr6p-63pg-hr6g published
Jul 28, 2026 by mmgueroModerate -
Raw-stream and Lzip Uploads Bypass Malcolm's Archive-Bomb ProtectionsGHSA-f2v6-8cj4-mhr6 published
Jul 28, 2026 by mmgueroModerate -
Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS)GHSA-c35g-mgc3-95rx published
Jul 15, 2026 by mmgueroModerate -
Path Traversal in Archive Extraction Allows Arbitrary Directory CreationGHSA-65mm-vgrw-vqx4 published
Jul 15, 2026 by mmgueroModerate -
Authorization Bypass via URI Normalization Differential in Nginx Lua RBACGHSA-m5fr-rv3h-xg2r published
Jul 23, 2026 by mmgueroHigh -
RCE via unrestricted .php upload to the file-upload componentGHSA-8cvp-m7pg-qrp7 published
Jun 15, 2026 by mmgueroHigh
Learn more about advisories related to cisagov/Malcolm in the GitHub Advisory Database