PatchSiren

CISAgov CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH CISAgov CVE published 2026-08-18

CVE-2026-19671

CVE-2026-19671 is a vulnerability in Malcolm's upload-processing pipeline that allows an authenticated user to upload a highly compressible file, which can decompress to an effectively unbounded size on disk, exhausting the shared Docker volume and disrupting the platform for all users. The vulnerability is caused by the lack of limits on single-stream compressed formats (.gz, .bz2, .xz, .lz) in Malcolm's [truncated]