Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-63177

Опубликовано: 11 авг. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized ngx.var.request_uri, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can prepend a traversal segment (for example /x/../upload/...) so that Nginx routes the request to a restricted backend while the Lua role check fails to match any rule and falls open, granting access it should deny. Version 26.07.0 fixes the issue.

EPSS

Процентиль: 8%
0.00178
Низкий

7.1 High

CVSS3

Дефекты

CWE-863

EPSS

Процентиль: 8%
0.00178
Низкий

7.1 High

CVSS3

Дефекты

CWE-863