PT-2026-77278 · Zeek+4 · Zeek+4
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Malcolm (affected versions not specified)
Description
The upload-processing pipeline in
scripts/safe-extract.py fails to apply entry-count, nesting-depth, and total-uncompressed-byte limits when processing single-stream compressed formats such as .gz, .bz2, .xz, .lzma, and .lz that are not .tar.*-style archives. This allows an authenticated user with upload permissions for PCAP or log files to upload a highly compressible file, such as a gzip bomb (a malicious archive designed to crash a system by expanding to an enormous size), which can exhaust the shared Docker volume used by OpenSearch, Logstash, Arkime, and Zeek, leading to platform disruption for all users.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arkime
Logstash
Malcolm
Opensearch
Zeek