PT-2026-22408 · Unknown · Malcontent

·

CVE-2026-28407

·

Published

2026-02-27

·

Updated

2026-07-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions malcontent versions prior to 1.21.0
Description malcontent is software used to discover supply-chain compromises through context, differential analysis, and YARA. A logic error exists where the software removes nested archives that fail to extract, which can lead to the omission of malicious content from scan inputs and allow detection bypass.
Recommendations Update to version 1.21.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28407
GHSA-945P-3JHM-6RCP
GO-2026-4577
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1042-1

Affected Products

Malcontent