VDB

CVE-2026-28407

CVE-2026-28407 PUBLISHED CVSS 6.900000095367432 MEDIUM

malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior to version 1.21.0, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes. Version 1.21.0 fixes the issue.

EPSS 0.04% · 11.0th percentile

Risk Scores

CVSS v4.0
6.900000095367432
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.04%
11.0th percentile

Affected Products

VendorProductVersions
chainguard-devmalcontent< 1.21.0, < 1.21.0
github.comchainguard-dev/malcontent0, 0
chainguardmalcontent0, 0

Timeline

  • Feb 27, 2026 CVE ID Reserved
  • Feb 27, 2026 CVE Published
  • Feb 28, 2026 EPSS Score
  • Feb 28, 2026 PoC Published
  • Mar 1, 2026 EPSS Score
  • Mar 2, 2026 CVE Updated
  • Mar 3, 2026 EPSS Score
  • Mar 4, 2026 EPSS Score
  • Mar 6, 2026 EPSS Score
  • Mar 7, 2026 EPSS Score
  • Mar 8, 2026 EPSS Score
  • Mar 10, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›