CVE-2026-63133: CWE-770: Allocation of Resources Without Limits or Throttling in cisagov Malcolm
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries causes the filebeat processing container to create an unbounded number of filesystem objects, exhausting inodes or filesystem metadata and denying service to the processing pipeline and any service sharing the same mount. Version 26.07.0 fixes the issue.
AI Analysis
Technical Summary
Malcolm is a network traffic analysis tool suite. In versions before 26.07.0, the safe-extract.py script does not impose limits on the number of entries, directory depth, total entries, or output size when extracting uploaded archives. This lack of throttling allows a crafted archive with a large number of directory or file entries to cause the filebeat processing container to create an unbounded number of filesystem objects. This resource exhaustion can deplete inodes or filesystem metadata, resulting in denial of service affecting the processing pipeline and any other services sharing the same filesystem mount. The issue is fixed in version 26.07.0.
Potential Impact
The vulnerability can cause denial of service by exhausting filesystem resources such as inodes or metadata. This disrupts the filebeat processing container and any other services sharing the same mount point, potentially impacting availability of the Malcolm processing pipeline.
Mitigation Recommendations
Upgrade to Malcolm version 26.07.0 or later, where the safe-extract.py script includes limits to prevent unbounded resource allocation during archive extraction. Patch status is not explicitly stated, but the issue is fixed in version 26.07.0. Check the vendor advisory for the latest remediation guidance.
CVE-2026-63133: CWE-770: Allocation of Resources Without Limits or Throttling in cisagov Malcolm
Description
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries causes the filebeat processing container to create an unbounded number of filesystem objects, exhausting inodes or filesystem metadata and denying service to the processing pipeline and any service sharing the same mount. Version 26.07.0 fixes the issue.
CVSS v3.1
Score 6.5medium
Affected software
cisagov
Malcolm
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Malcolm is a network traffic analysis tool suite. In versions before 26.07.0, the safe-extract.py script does not impose limits on the number of entries, directory depth, total entries, or output size when extracting uploaded archives. This lack of throttling allows a crafted archive with a large number of directory or file entries to cause the filebeat processing container to create an unbounded number of filesystem objects. This resource exhaustion can deplete inodes or filesystem metadata, resulting in denial of service affecting the processing pipeline and any other services sharing the same filesystem mount. The issue is fixed in version 26.07.0.
Potential Impact
The vulnerability can cause denial of service by exhausting filesystem resources such as inodes or metadata. This disrupts the filebeat processing container and any other services sharing the same mount point, potentially impacting availability of the Malcolm processing pipeline.
Mitigation Recommendations
Upgrade to Malcolm version 26.07.0 or later, where the safe-extract.py script includes limits to prevent unbounded resource allocation during archive extraction. Patch status is not explicitly stated, but the issue is fixed in version 26.07.0. Check the vendor advisory for the latest remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-15T16:54:55.817Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7b8c91bf8831d539668d27
Added to database: 08/11/2026, 20:56:49 UTC
Last enriched: 08/11/2026, 21:12:28 UTC
Last updated: 09/25/2026, 13:47:47 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.