Description
A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context.
Published: 2026-09-11
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Limited exploitation potential; no remote code execution
Action: Patch
AI Analysis

Impact

A prior update that upgraded the bundled HTTP client library to a version that had known vulnerabilities was later rolled back, reintroducing the older, vulnerable client into Malcolm’s log‑processing component. The only path that uses this library is an initialization call that makes a single, outbound request to a fixed, trusted vendor URL, and no user‑controlled input is passed to the library. to execute arbitrary code or alter data directly; its potential impact is limited to flaws that might be triggered during that outbound call.

Affected Systems

Malcolm, a log‑processing tool developed by CISA, is affected. Any build that contains the legacy HTTP client library in its log‑processing module carries the vulnerability. The specific version numbers are not disclosed, so any instance with the reverted older library is potentially at risk.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, yet the EPSS score of less than 1% signals a very low probability of active exploitation. Because the vulnerable library is used only for an outbound request to a known, trusted vendor endpoint and no attacker‑controlled data reaches it, the risk of exploitation is minimal. An attacker would need to compromise or spoof that vendor endpoint before the vulnerable client could be triggered, a scenario that is unlikely under normal operation. The vulnerability is not listed in the CISA KEV catalog, further indicating its limited threat surface.

Generated by OpenCVE AI on September 15, 2026 at 20:52 UTC.

Remediation

Vendor Solution

The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.


OpenCVE Recommended Actions

  • Upgrade Malcolm to the latest release ( the vulnerable client library.
  • Configure network controls so that Malcolm can reach only the known vendor URL, blocking all other outbound HTTP/HTTPS traffic.
  • Review the codebase to ensure no legacy HTTP client library remains in use and monitor outbound connections for anomalous activity.

Generated by OpenCVE AI on September 15, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Reintroduced Vulnerable HTTP Client in Malcolm Log-Processing

Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Reintroduced Vulnerable HTTP Client in Malcolm Log-Processing

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Legacy HTTP Client Library Reintroduction in Malcolm Log-Processing Component

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Legacy HTTP Client Library Reintroduction in Malcolm Log-Processing Component

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisagov
Cisagov malcolm
Vendors & Products Cisagov
Cisagov malcolm

Sun, 13 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Legacy HTTP Client Reintroduced in Malcolm Log-Processing Component

Sun, 13 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title Legacy HTTP Client Reintroduced in Malcolm Log-Processing Component

Sat, 12 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Reintroduced Vulnerable HTTP Client Library in Malcolm Log-Processing Component

Sat, 12 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Reintroduced Vulnerable HTTP Client Library in Malcolm Log-Processing Component

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context.
Weaknesses CWE-1395
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-14T13:00:29.977Z

Reserved: 2026-09-11T21:00:09.301Z

Link: CVE-2026-90455

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:17.393Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T22:16:47.873

Modified: 2026-09-18T19:40:31.053

Link: CVE-2026-90455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:00:17Z

Weaknesses
  • CWE-1395

    Dependency on Vulnerable Third-Party Component