{"api_version":"v1","generated_at":"2026-10-07T17:40:00+00:00","product":{"cve_count":15,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-cisa-malcolm-60ee660a1e60","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/malcolm","name":"Malcolm","next_cursor":null,"observations":[{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90457","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90457","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T20:43:26.818Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:52:36.941Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90456","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90456","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T20:46:04.083Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:52:17.371Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90455","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90455","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T20:48:25.343Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:51:59.698Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90454","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90454","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T20:54:31.559Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:51:42.586Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90453","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90453","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T20:56:51.481Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:51:25.668Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90452","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90452","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T20:59:14.755Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:51:08.628Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90451","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90451","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T21:01:17.130Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:50:31.920Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90450","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90450","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T21:03:30.507Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:50:11.417Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90449","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90449","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T21:07:51.750Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:49:50.744Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90448","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90448","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T21:09:57.540Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:49:12.225Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90447","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90447","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T21:12:27.669Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:48:51.996Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90446","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90446","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T21:14:48.767Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:48:29.440Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90445","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90445","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T21:16:30.467Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:48:01.174Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90444","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90444","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T21:18:08.661Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:46:07.809Z"},{"affected":"Malcolm: < v26.06.0","affected_versions_present":true,"cve_id":"CVE-2026-90443","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90443","fixed":"Malcolm: v26.06.0","last_modified":"2026-10-02T21:20:09.751Z","patch_url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-254-01.json","primary_source":"","published":"2026-09-11T21:45:27.831Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"CISA"}}
