216.73.216.226

CVE-2026-28407

· Published 27/02/2026 22:16 · Modified 27/02/2026 22:16

Labels: CVE-2026-28407 2026-02-27CVE-2026-28407CWE-703[email protected]

Essential information

Published
27/02/2026 22:16
Modified
27/02/2026 22:16
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes. Version 1.21.0 fixes the issue.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
malcontent / malcontent cpe:2.3:a:malcontent:malcontent:*:*:*:*:*:*:*:*

References