What is CVE-2026-63133?
CVE-2026-63133 is a vulnerability in the Malcolm network traffic analysis tool where `safe-extract.py` extracts uploaded archives without limits on entry count, directory depth, total entries, or output size. In affected versions prior to 26.07.0, a small malicious archive can cause filebeat to fail. Upgrading Malcolm to version 26.07.0 or later is recommended.
Azərbaycanca: CVE-2026-63133 Malcolm şəbəkə trafiki analiz alətində `safe-extract.py` skriptində yüklənən arxivləri çıxararkən element sayı, qovluq dərinliyi və ümumi ölçü limitinin olmaması zəifliyidir. Təsirə məruz qalan versiyalarda kiçik zərərli arxiv filebeat-in sıradan çıxmasına səbəb ola bilər. Malcolm-ı 26.07.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which component of the Malcolm tool is affected by CVE-2026-63133?
This vulnerability affects the `safe-extract.py` script in the Malcolm network traffic analysis tool.
To what version should Malcolm be upgraded to address CVE-2026-63133?
It is recommended to upgrade Malcolm to version 26.07.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.