# CVE-2026-90455

## Summary

- **CVE ID:** CVE-2026-90455
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-1395
- **Published:** Sep 11, 2026
- **Last Modified:** Sep 14, 2026

## Description

A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a single fixed, trusted vendor URL at initialization and does not process attacker-controlled input through the library, limiting practical exploitability of the reintroduced version in this context.

## Affected Products

- CISA — Malcolm (0)
- CISA — Malcolm (v26.06.0)

## References

- [CNA](https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.22%
- **EPSS Percentile:** 12.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._