GHSA-54p8-x2m9-c593

Suggest an improvement
Source
https://github.com/advisories/GHSA-54p8-x2m9-c593
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-54p8-x2m9-c593/GHSA-54p8-x2m9-c593.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-54p8-x2m9-c593
Aliases
Published
2026-03-02T18:48:03Z
Modified
2026-03-23T04:56:28Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
malcontent: Error-path cleanup gap can leak scanners and fds and degrade availability
Details

Several extraction and scanning code paths registered late defers which could leak resources and exhaust system resources.

This report is an aggregate of these individual reports for the affected code:

Advisory Affected File
GHSA-jjgh-mc5q-gch7 pkg/action/scan.go
GHSA-mwmf-fxh2-w4x7 pkg/archive/deb.go
GHSA-p8j3-rpf5-gwv3 pkg/archive/gzip.go
GHSA-qfh4-7f5v-75gq pkg/archive/zlib.go
GHSA-wxxf-r586-5rf5 pkg/archive/bzip2.go

Fix: #1354, #1355, #1356, #1361

Acknowledgements

Thank you to Oleh Konko from 1seal for discovering and reporting all six of these issues.

Database specific
{
    "cwe_ids": [
        "CWE-400"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-02T18:48:03Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

Go / github.com/chainguard-dev/malcontent

Package

Name
github.com/chainguard-dev/malcontent
View open source insights on deps.dev
Purl
pkg:golang/github.com/chainguard-dev/malcontent

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.21.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-54p8-x2m9-c593/GHSA-54p8-x2m9-c593.json"