Impact
A prior update that upgraded the bundled HTTP client library to a version that had known vulnerabilities was later rolled back, reintroducing the older, vulnerable client into Malcolm’s log‑processing component. The only path that uses this library is an initialization call that makes a single, outbound request to a fixed, trusted vendor URL, and no user‑controlled input is passed to the library. to execute arbitrary code or alter data directly; its potential impact is limited to flaws that might be triggered during that outbound call.
Affected Systems
Malcolm, a log‑processing tool developed by CISA, is affected. Any build that contains the legacy HTTP client library in its log‑processing module carries the vulnerability. The specific version numbers are not disclosed, so any instance with the reverted older library is potentially at risk.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, yet the EPSS score of less than 1% signals a very low probability of active exploitation. Because the vulnerable library is used only for an outbound request to a known, trusted vendor endpoint and no attacker‑controlled data reaches it, the risk of exploitation is minimal. An attacker would need to compromise or spoof that vendor endpoint before the vulnerable client could be triggered, a scenario that is unlikely under normal operation. The vulnerability is not listed in the CISA KEV catalog, further indicating its limited threat surface.
OpenCVE Enrichment