Denial of Service Vulnerability in ClamAV Zip Archive Parser
CVE-2026-20338

7.5HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
7 August 2026

Badges

👾 Exploit Exists

What is CVE-2026-20338?

A flaw in the zip archive parser of ClamAV allows remote, unauthenticated attackers to trigger a Denial of Service condition. This vulnerability arises from improper memory management during the processing of zip file contents, particularly when scanning. An attacker can exploit this flaw by submitting a specially crafted zip file, potentially leading to a memory double-free scenario. This can cause the ClamAV scanning engine to terminate unexpectedly, impacting the software's reliability and accessibility.

Affected Version(s)

Cisco Secure Endpoint 7.0.5

Cisco Secure Endpoint 6.2.19

Cisco Secure Endpoint 7.3.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.