CVE-2026-20031

Name
CVE-2026-20031
Description
A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when splitting UTF-8 strings. An attacker could exploit this vulnerability by submitting a crafted HTML file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the scanning process.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
psirt@cisco.com https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-css-Fn4QSZ

Match rules

CPE URI Source package Min version Max version

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
clamav edge-community 1.4.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
clamav 3.24-community 1.4.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed
clamav 3.23-community 1.4.4-r0 Carlo Landmeter <clandmeter@alpinelinux.org> fixed