FlawAtlas
Search the atlas
CVE-2026-28407 Moderate

malcontent: Nested archive extraction failure can drop content from scan inputs in github.com/chainguard-dev/malcontent

malcontent: Nested archive extraction failure can drop content from scan inputs in github.com/chainguard-dev/malcontent

Exploit probability 0.4%
Published March 10, 2026
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

96 explicit affected versions

Go github.com/chainguard-dev/malcontent
Go github.com/chainguard-dev/malcontent

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-28407

malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes. Version 1.21.0 fixes the issue.

View original source
Open Source Vulnerabilities GHSA-945p-3jhm-6rcp

Previously, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes. **Fix**: https://github.com/chainguard-dev/malcontent/pull/1383 **Acknowledgements** malcontent thanks Oleh Konko from [1seal](https://1seal.org/) for discovering and reporting this issue.

View original source
Open Source Vulnerabilities GO-2026-4577

malcontent: Nested archive extraction failure can drop content from scan inputs in github.com/chainguard-dev/malcontent

View original source

05 / REFERENCES

Further evidence