PT-2026-77278 · Zeek+4 · Zeek+4

·

CVE-2026-19671

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Malcolm (affected versions not specified)
Description The upload-processing pipeline in scripts/safe-extract.py fails to apply entry-count, nesting-depth, and total-uncompressed-byte limits when processing single-stream compressed formats such as .gz, .bz2, .xz, .lzma, and .lz that are not .tar.*-style archives. This allows an authenticated user with upload permissions for PCAP or log files to upload a highly compressible file, such as a gzip bomb (a malicious archive designed to crash a system by expanding to an enormous size), which can exhaust the shared Docker volume used by OpenSearch, Logstash, Arkime, and Zeek, leading to platform disruption for all users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19671
GHSA-F2V6-8CJ4-MHR6

Affected Products

Arkime
Logstash
Malcolm
Opensearch
Zeek