Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reintroduced Vulnerable HTTP Client in Malcolm Log-Processing |
Tue, 15 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reintroduced Vulnerable HTTP Client in Malcolm Log-Processing |
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Legacy HTTP Client Library Reintroduction in Malcolm Log-Processing Component |
Mon, 14 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Legacy HTTP Client Library Reintroduction in Malcolm Log-Processing Component |
Sun, 13 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisagov
Cisagov malcolm |
|
| Vendors & Products |
Cisagov
Cisagov malcolm |
Sun, 13 Sep 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Legacy HTTP Client Reintroduced in Malcolm Log-Processing Component |
Sun, 13 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Legacy HTTP Client Reintroduced in Malcolm Log-Processing Component |
Sat, 12 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reintroduced Vulnerable HTTP Client Library in Malcolm Log-Processing Component |
Sat, 12 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reintroduced Vulnerable HTTP Client Library in Malcolm Log-Processing Component |
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context. | |
| Weaknesses | CWE-1395 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-09-14T13:00:29.977Z
Reserved: 2026-09-11T21:00:09.301Z
Link: CVE-2026-90455
Updated: 2026-09-14T12:57:17.393Z
Status : Received
Published: 2026-09-11T22:16:47.873
Modified: 2026-09-14T13:19:29.293
Link: CVE-2026-90455
No data.
OpenCVE Enrichment
Updated: 2026-09-15T21:00:17Z