Denial of Service Vulnerability in ClamAV's HTML Cascading Style Sheets Module
CVE-2026-20031
What is CVE-2026-20031?
A vulnerability exists in the HTML Cascading Style Sheets (CSS) module of ClamAV, enabling an unauthenticated remote attacker to induce a denial of service (DoS) on affected devices. The flaw arises from improper error handling during the process of splitting UTF-8 strings. By submitting a specifically crafted HTML file for scanning, an attacker can disrupt the scanning process, thereby compromising the availability of the service. This presents a potential risk for systems relying on ClamAV for malware protection.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Secure Endpoint 7.0.5
Cisco Secure Endpoint 6.2.19
Cisco Secure Endpoint 7.3.3
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved