[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-cisa-fixes-six-flaws-in-its-malcolm-network-forensics-tool":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},5653,"cisa-fixes-six-flaws-in-its-malcolm-network-forensics-tool","CISA Fixes Six Flaws in Its Malcolm Network Forensics Tool","A missing file-type check let low-privileged Malcolm users run PHP code, one of six flaws CISA just disclosed in its own traffic-analysis tool.","CISA disclosed six vulnerabilities in Malcolm, the network traffic analysis suite it maintains, and the worst lets a low-privileged user run arbitrary code on the server.\n\nThat flaw, CVE-2026-55676, comes from an upload filter that ships with an empty allow-list, so every file extension is accepted by default and a renaming step fails to strip .php. Because nginx forwards any .php request to the PHP interpreter, and because the upload endpoint is reachable by a role meant only for submitting capture files, a low-privileged user can plant and run a web shell as www-data. CISA rates that one 8.8 out of 10 and Malcolm fixed it in version 26.06.1. The other five, patched in versions 26.07.0 and 26.08.0, are not one bug repeated five times. Two of them, CVE-2026-63177 and CVE-2026-19670, share a root cause: Malcolm's access-control layer checks a different version of the request URL than nginx uses to route it, so a crafted or encoded path slips past the role check into an admin-only page. The remaining three sit in the file-extraction pipeline and are unrelated to each other: CVE-2026-63133 lets a tiny archive spawn unlimited directory entries and exhaust the server's inodes, CVE-2026-63134 lets a crafted directory entry escape the intended extraction folder, and CVE-2026-19671 lets a plain .gz file dodge the extraction size limits entirely, acting as a compression bomb.\n\nMalcolm is CISA's own tool, built for defenders to inspect network traffic, and it's deployed across IT networks worldwide according to the advisory. A pile of six separate bugs, spanning upload validation, access control, and archive handling, says less about any one coding mistake than about how much attack surface a self-hosted analysis suite carries once you add file uploads and role-based admin panels.\n\nA tool built to catch attackers on other people's networks spent this cycle finding new ways to mishandle its own file uploads.","[\"cisa\",\"malcolm\",\"vulnerabilities\",\"open-source\"]","2026-08-18T12:00:00.000Z","2026-08-19T07:21:07.790Z","2026-08-19T07:21:19.628Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The 'four of the six bugs trace back to the same root cause' claim is wrong — only CVE-2026-63177 and CVE-2026-19670 involve the URL-mismatch root cause (two bugs, not four); rework the analysis paragraph and the 'two families' breakdown so it correctly accounts for all five non-headline CVEs, including the unmentioned CVE-2026-63133 (unbounded archive entries exhausting inodes) and CVE-2026-63134 (path traversal in archive extraction).","resolved","security",[32,33,34,35],"cisa","malcolm","vulnerabilities","open-source",[37],{"name":38,"url":39},"CISA Advisories","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-230-01",0,{"sections":42},[43,48,51,56,61,66,71,76,81,86,91,96,101,106],{"name":44,"slug":45,"count":46,"latest_published_at":47},"AI","ai",3293,"2026-08-20T04:00:00.000Z",{"name":49,"slug":30,"count":50,"latest_published_at":47},"Security",435,{"name":52,"slug":53,"count":54,"latest_published_at":55},"Policy","policy",210,"2026-08-19T09:32:27.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Hardware","hardware",140,"2026-08-19T18:25:42.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Consumer Tech","consumer-tech",95,"2026-08-18T16:05:00.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Science","science",90,"2026-08-19T18:41:02.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Startups","startups",47,"2026-08-19T19:13:46.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"General","general",33,"2026-08-18T22:18:13.000Z",{"name":102,"slug":103,"count":104,"latest_published_at":105},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":107,"slug":108,"count":109,"latest_published_at":110},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]