PatchSiren cyber security CVE debrief
CVE-2026-107335 CISA CVE debrief
CVE-2026-107335 Improper Handling of Highly Compressed Data in Malcolm allows authenticated users to disrupt the platform via highly compressible files. The vulnerability exists in Malcolm's upload-processing pipeline, which does not apply limits when extracting single-stream compressed formats. This can lead to potential disruption of the Malcolm platform for all users, exhaustion of shared Docker volume resources, and possible impact on OpenSearch, Logstash, Arkime, and Zeek functionality.
- Vendor
- CISA
- Product
- Malcolm
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Authenticated users with upload permissions, administrators of Malcolm installations, security teams responsible for monitoring and mitigating potential impacts, and operators of affected platforms should review the vulnerability and take necessary actions to mitigate potential impacts.
Why it matters
CVE-2026-107335 allows authenticated users to disrupt the Malcolm platform via highly compressible files, requiring review of upload permissions and monitoring of uploaded file sizes.
- Potential disruption of the Malcolm platform for all users
- Exhaustion of shared Docker volume resources
- Possible impact on OpenSearch, Logstash, Arkime, and Zeek functionality
Technical summary
Malcolm's upload-processing pipeline does not apply limits when extracting single-stream compressed formats, allowing authenticated users to upload highly compressible files that can decompress to an effectively unbounded size, exhausting the shared Docker volume and disrupting the platform. The vulnerability exists in the upload-processing pipeline (scripts/safe-extract.py) and affects the platform's functionality, including OpenSearch, Logstash, Arkime, and Zeek. Defenders should review compensating controls for exposed systems while remediation is scheduled and verified.
Defensive priority
Medium priority for authenticated users with upload permissions
Recommended defensive actions
- Review and limit upload permissions for authenticated users
- Monitor and restrict the size of uploaded files
- Implement additional validation and filtering for compressed files
- Consider applying compensating controls to mitigate potential impact
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability in Malcolm's upload-processing pipeline. The NVD entry is currently UNCHANGED. The vulnerability allows authenticated users to upload highly compressible files that can decompress to an effectively unbounded size, exhausting the shared Docker volume and disrupting the platform. Defenders should verify the affected scope, severity, and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107335 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107335
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107335 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107335
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Improper Handling of Highly Compressed Data in Malcolm
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107335.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/Malcolm/security/advisories/GHSA-jr6p-63pg-hr6g
Supplemental source - government-resource
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-280-01.json
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.