Denial of Service Vulnerability in ClamAV Zip Archive Parser
CVE-2026-20338
7.5HIGH
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 7 August 2026
Badges
๐พ Exploit Exists๐ฐ News Worthy
What is CVE-2026-20338?
A flaw in the zip archive parser of ClamAV allows remote, unauthenticated attackers to trigger a Denial of Service condition. This vulnerability arises from improper memory management during the processing of zip file contents, particularly when scanning. An attacker can exploit this flaw by submitting a specially crafted zip file, potentially leading to a memory double-free scenario. This can cause the ClamAV scanning engine to terminate unexpectedly, impacting the software's reliability and accessibility.
Affected Version(s)
Cisco Secure Endpoint 7.0.5
Cisco Secure Endpoint 6.2.19
Cisco Secure Endpoint 7.3.3
News Articles
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- ๐ฐ
First article discovered by BleepingComputer
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved