CVE-2026-28407: malcontent's nested archive extraction failure can drop content from scan inputs

Published Feb 27, 2026
·
Updated

malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes. Version 1.21.0 fixes the issue.

Other sources

Previously, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes.

Fix: https://github.com/chainguard-dev/malcontent/pull/1383

Acknowledgements

malcontent thanks Oleh Konko from 1seal for discovering and reporting this issue.

— GitHub

Affected Software

3 affected componentsFixes available
npm/malcontent<1.21.0
go/github.com/chainguard-dev/malcontent<1.21.0
1.21.0
chainguard malcontent<1.21.0

Event History

Feb 27, 2026
CVE Published
via MITRE·09:28 PM
Data Sourced
via MITRE·09:28 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 28, 2026
Advisory Published
via GitHub·02:50 AM
Data Sourced
via GitHub·02:50 AM
DescriptionWeaknessAffected Software
Mar 23, 58145
Event
via FIRST·06:00 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-28407?

CVE-2026-28407 is considered a moderate severity vulnerability affecting malcontent versions prior to 1.21.0.

2

How do I fix CVE-2026-28407?

To fix CVE-2026-28407, upgrade malcontent to version 1.21.0 or later.

3

What can be exploited in CVE-2026-28407?

CVE-2026-28407 can lead to the loss of content from nested archives during extraction due to a failure in handling these files.

4

Is CVE-2026-28407 specific to certain versions of malcontent?

Yes, CVE-2026-28407 specifically affects malcontent versions before 1.21.0.

5

What is the impact of CVE-2026-28407 on software security?

The impact of CVE-2026-28407 is that it may result in incomplete analysis and detection of supply-chain compromises due to lost data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203