Back

MEDIUM

Dependency on vulnerable third-party component in Malcolm

Published Sep 11, 2026

Description

A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context.

Affected products

Remediation

Vendor solution

The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Sep 11, 2026
Updated Oct 2, 2026
Reserved Sep 11, 2026
CISA Vulnrichment
Updated Sep 14, 2026
NVD
Status Awaiting Analysis
Modified Oct 2, 2026
Red Hat
Severity n/a
Public date n/a