CVE-2026-28407

malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes. Version 1.21.0 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:chainguard:malcontent:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:28

Type Values Removed Values Added
Summary
  • (es) malcontent es un software para descubrir compromisos en la cadena de suministro mediante contexto, análisis diferencial y YARA. Antes de la versión 1.21.0, malcontent eliminaba los archivos anidados que no se pudieron extraer, lo que podría dejar contenido malicioso. Un enfoque mejor es preservar estos archivos para que malcontent pueda intentar un escaneo de mejor esfuerzo de los bytes del archivo. La versión 1.21.0 corrige el problema.

03 Mar 2026, 18:23

Type Values Removed Values Added
CPE cpe:2.3:a:chainguard:malcontent:*:*:*:*:*:*:*:*
First Time Chainguard malcontent
Chainguard
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
References () https://github.com/chainguard-dev/malcontent/commit/356c56659ccfcad0b249a97de8cf71f151ed3ee9 - () https://github.com/chainguard-dev/malcontent/commit/356c56659ccfcad0b249a97de8cf71f151ed3ee9 - Patch
References () https://github.com/chainguard-dev/malcontent/pull/1383 - () https://github.com/chainguard-dev/malcontent/pull/1383 - Issue Tracking, Patch
References () https://github.com/chainguard-dev/malcontent/security/advisories/GHSA-945p-3jhm-6rcp - () https://github.com/chainguard-dev/malcontent/security/advisories/GHSA-945p-3jhm-6rcp - Patch, Vendor Advisory

27 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-27 22:16

Updated : 2026-06-17 10:28


NVD link : CVE-2026-28407

Mitre link : CVE-2026-28407

CVE.ORG link : CVE-2026-28407


JSON object : View

Products Affected

chainguard

  • malcontent
CWE
CWE-703

Improper Check or Handling of Exceptional Conditions