CVE-2026-63177

Summary

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized ngx.var.request_uri, while Nginx itself routes requests using the normalized path. An authenticated low-privilege user can prepend a traversal segment (for example /x/../upload/...) so that Nginx routes the request to a restricted backend while the Lua role check fails to match any rule and falls open, granting access it should deny. Version 26.07.0 fixes the issue.

Affected Software

VendorProductVersion RangeStatus
cisagovMalcolm< 26.07.0affected

Weaknesses

  • CWE-863: CWE-863: Incorrect Authorization

References