mediumCVSS 5.3Vulnerability

GHSA-54p8-x2m9-c593

Several extraction and scanning code paths registered late defers which could leak resources and exhaust system resources. This report is an aggregate of these individual reports for the affected code: Advisory | Affected File -- | -- `GHSA-jjgh-mc5q-gch7` | `pkg/action/scan.go` `GHSA-mwmf-fxh2-w4x7` | `pkg/archive/deb.go` `GHSA-p8j3-rpf5-gwv3` | `pkg/archive/gzip.go` `GHSA-qfh4-7f5v-75gq` | `pkg/archive/zlib.go` `GHSA-wxxf-r586-5rf5` | `pkg/archive/bzip2.go` **Fix**: #1354, #1355, #1356, #1361 **Acknowledgements** Thank you to Oleh Konko from [1seal](https://1seal.org/) for discovering and reporting all six of these issues.

Properties

ghsa_id
GHSA-54p8-x2m9-c593
severity
medium
summary
malcontent: Error-path cleanup gap can leak scanners and fds and degrade availability
cvss_score
5.3
cve_id
GHSA-54p8-x2m9-c593
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
is_ghsa_only
true
ghsa_published
2026-03-02T18:48:03Z
source_url
https://github.com/advisories/GHSA-54p8-x2m9-c593
ghsa_updated
2026-03-02T18:48:04Z

Related Entities (3)

AFFECTS (1)

[Software]go/github.com/chainguard-dev/malcontent

HAS_WEAKNESS (1)

[Weakness]Uncontrolled Resource Consumption

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph