CVE-2026-90455
A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.22%
- CWE
- CWE-1395
- Published
- 2026-09-11
- Last modified
- 2026-09-14
Affected products
- CISA Malcolm
- CISA Malcolm
Weakness type
Related vulnerabilities
- CVE-2024-5246 — NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability
- CVE-2024-11948 — GFI Archiver Telerik Web UI Remote Code Execution Vulnerability
- CVE-2025-12220 — Busybox 1.31.1 - Multiple Known Vulnerabilities
- CVE-2025-12219 — Vulnerable Components in Azure Access OS
- CVE-2026-4176 — Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib
- CVE-2025-10226 — PostgreSQL Upgrade from v10 to v17.4 in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier to Address Multiple Vulnerabilities
- CVE-2024-0552 — Intumit inc. SmartRobot - Remote Code Execution
- CVE-2024-26293 — Unauthenticated Path Traversal affecting Avid NEXIS