Error-path cleanup gap can leak scanners and fds and degrade availability
Fixed in: malcontent v1.21.0
patched
details
Finding IDs
F-MALCONTENT-006
GHSA
GHSA-54p8-x2m9-c593
Status
patched
Fixed in
malcontent v1.21.0
Note
primary mapping; advisory text matches the late-defer/resource-leak fix train
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Upstream title
Error-path cleanup gap can leak scanners and fds and degrade availability
Upstream CWE
CWE-400
Upstream publication
Upstream updated
Metadata fetched
Upstream @1seal credit
@1seal: reporter (accepted)
F-MALCONTENT-006: Resource limits. Scanner resources and file descriptors are not reliably released. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Public PR metadata recorded in the 2026-09-24 evidence audit; not a live status feed.
Contribution boundary
Report-associated upstream work; @1seal code authorship is not claimed. Credit, where recorded, is a separate fact.
F-MALCONTENT-006: Resource limits. Scanner resources and file descriptors are not reliably released. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.