malcontent: Nested archive extraction failure can drop content from scan inputs
Package
Affected versions
< 1.21.0
Patched versions
1.21.0
Description
Published by the National Vulnerability Database
Feb 27, 2026
Published to the GitHub Advisory Database
Feb 28, 2026
Reviewed
Feb 28, 2026
Previously, malcontent would remove nested archives which failed to extract which could potentially leave malicious content. A better approach is to preserve these archives so that malcontent can attempt a best-effort scan of the archive bytes.
Fix: chainguard-dev/malcontent#1383
Acknowledgements
malcontent thanks Oleh Konko from 1seal for discovering and reporting this issue.
References