Dependency on vulnerable third-party component in Malcolm
Published Sep 11, 2026
6.3
MEDIUMCVSS 4.0
EPSS 0.20%
Description
A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context.
Affected products
-
- Version 0StatusaffectedConstraints<v26.06.0
- Version v26.06.0StatusunaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.
References (2)
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json government-resourcevendor-advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01
| Link | Providers | Tags |
|---|---|---|
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json | government-resourcevendor-advisory | |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-254-01 |
Change history (0)
No recorded changes yet.