HIGH
CISAgov
CVE published 2026-08-18
CVE-2026-19671
CVE-2026-19671 is a vulnerability in Malcolm's upload-processing pipeline that allows an authenticated user to upload a highly compressible file, which can decompress to an effectively unbounded size on disk, exhausting the shared Docker volume and disrupting the platform for all users. The vulnerability is caused by the lack of limits on single-stream compressed formats (.gz, .bz2, .xz, .lz) in Malcolm's [truncated]