CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107335

MEDIUMCVSS 6.5NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream compressed format (.gz

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-107335 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-107335

MEDIUMCVSS 6.5NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream compressed format (.gz

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]