Skip to content

Nested archive extraction failure can drop content from scan inputs

Moderate
egibs published GHSA-945p-3jhm-6rcp Feb 27, 2026

Package

No package listed

Affected versions

< v1.21.0

Patched versions

v1.21.0

Description

Previously, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes.

Fix: #1383

Acknowledgements

Thank you to Oleh Konko from 1seal for discovering and reporting this issue.

Severity

Moderate

CVE ID

CVE-2026-28407

Weaknesses

Improper Check or Handling of Exceptional Conditions

The product does not properly anticipate or handle exceptional conditions that rarely occur during normal operation of the product. Learn more on MITRE.

Credits