{"id":"GHSA-54p8-x2m9-c593","aliases":["GO-2026-4583"],"url":"https://o3.security/vulnerability/GHSA-54p8-x2m9-c593","summary":"malcontent: Error-path cleanup gap can leak scanners and fds and degrade availability","details":"Several extraction and scanning code paths registered late defers which could leak resources and exhaust system resources.\n\nThis report is an aggregate of these individual reports for the affected code:\nAdvisory | Affected File\n-- | --\n`GHSA-jjgh-mc5q-gch7` | `pkg/action/scan.go`\n`GHSA-mwmf-fxh2-w4x7` | `pkg/archive/deb.go`\n`GHSA-p8j3-rpf5-gwv3` | `pkg/archive/gzip.go`\n`GHSA-qfh4-7f5v-75gq` | `pkg/archive/zlib.go`\n`GHSA-wxxf-r586-5rf5` | `pkg/archive/bzip2.go`\n\n**Fix**: #1354, #1355, #1356, #1361\n\n**Acknowledgements**\n\nThank you to Oleh Konko from [1seal](https://1seal.org/) for discovering and reporting all six of these issues.","published":"2026-03-02T18:48:03Z","modified":"2026-03-23T04:56:28.838404712Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/chainguard-dev/malcontent","fixedVersion":"1.21.0"}],"fix":{"url":"https://github.com/chainguard-dev/malcontent/pull/1354","label":"chainguard-dev/malcontent#1354"},"references":[{"type":"WEB","url":"https://github.com/chainguard-dev/malcontent/security/advisories/GHSA-54p8-x2m9-c593"},{"type":"WEB","url":"https://github.com/chainguard-dev/malcontent/pull/1354"},{"type":"WEB","url":"https://github.com/chainguard-dev/malcontent/pull/1355"},{"type":"WEB","url":"https://github.com/chainguard-dev/malcontent/pull/1356"},{"type":"WEB","url":"https://github.com/chainguard-dev/malcontent/pull/1361"},{"type":"PACKAGE","url":"https://github.com/chainguard-dev/malcontent"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-23T04:56:28.838404712Z"}}