CVE-2026-28407: malcontent's nested archive extraction failure can drop content from scan inputs
malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes. Version 1.21.0 fixes the issue.
Other sources
Previously, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes.
Fix: https://github.com/chainguard-dev/malcontent/pull/1383
Acknowledgements
malcontent thanks Oleh Konko from 1seal for discovering and reporting this issue.
— GitHub
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28407?
CVE-2026-28407 is considered a moderate severity vulnerability affecting malcontent versions prior to 1.21.0.
How do I fix CVE-2026-28407?
To fix CVE-2026-28407, upgrade malcontent to version 1.21.0 or later.
What can be exploited in CVE-2026-28407?
CVE-2026-28407 can lead to the loss of content from nested archives during extraction due to a failure in handling these files.
Is CVE-2026-28407 specific to certain versions of malcontent?
Yes, CVE-2026-28407 specifically affects malcontent versions before 1.21.0.
What is the impact of CVE-2026-28407 on software security?
The impact of CVE-2026-28407 is that it may result in incomplete analysis and detection of supply-chain compromises due to lost data.