CVE-2026-19671
Published: August 18th, 2026
Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied when the uploaded file is a single-stream compressed format (.gz, .bz2, .xz, .lzma, .lz) that isn't a .tar.*-style archive. Any authenticated user permitted to upload PCAP/log files can upload a small, highly compressible file (e.g. a gzip bomb) that decompresses to an effectively unbounded size on disk, exhausting the shared Docker volume used by OpenSearch, Logstash, Arkime, and Zeek, and disrupting the platform for all users.
MEDIUM
CVSS v3: 6.5
CVSS v3: 6.5
Status
| DocFilters Release | Package | State | Justification | Comment |
|---|---|---|---|---|
| 22.3 | lzma (17.01) | Needs Triage | ||
| 22.2 | lzma (17.01) | Needs Triage | ||
| 22.1 | lzma (17.01) | Needs Triage | ||
| 21.11 | lzma (17.01) | Needs Triage | ||
| 21.8 | lzma (17.01) | Needs Triage | ||
| 21.5.0 | lzma (17.01) | Needs Triage | ||
| 21.2.0 | lzma (17.01) | Needs Triage | ||
| 11.4.19.3667 | lzma (17.01) | Needs Triage | ||
| 11.4.18.3599 | lzma (17.01) | Needs Triage | ||
| 11.4.16.3445 | lzma (17.01) | Needs Triage | ||
| 11.4.15.3368 | lzma (17.01) | Needs Triage | ||
| 11.4.14.3263 | lzma (17.01) | Needs Triage | ||
| 11.4.13.3179 | lzma (17.01) | Needs Triage | ||
| 11.4.12.3054 | lzma (17.01) | Needs Triage | ||
| 11.4.11.3040 | lzma (17.01) | Needs Triage | ||
| 11.4.11.2990 | lzma (17.01) | Needs Triage | ||
| 11.4.10.2934 | lzma (17.01) | Needs Triage | ||
| 11.4.9.2878 | lzma (17.01) | Needs Triage | ||
| 11.4.8.2822 | lzma (17.01) | Needs Triage |
Severity score breakdown
Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
HIGH
Base Score
6.5
Base Severity
MEDIUM
Confidentiality Impact
NONE
Integrity Impact
NONE
Privileges Required
LOW
Scope
UNCHANGED
User Interaction
NONE
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Version
3.1