CVE-2026-20031

A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when splitting UTF-8 strings. An attacker could exploit this vulnerability by submitting a crafted HTML file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the scanning process.
Configurations

No configuration.

History

17 Jun 2026, 10:16

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en el módulo HTML Cascading Style Sheets (CSS) de ClamAV podría permitir a un atacante remoto no autenticado causar una condición de denegación de servicio (DoS) en un dispositivo afectado. Esta vulnerabilidad se debe a un manejo de errores inadecuado al dividir cadenas UTF-8. Un atacante podría explotar esta vulnerabilidad al enviar un archivo HTML manipulado para ser escaneado por ClamAV en un dispositivo afectado. Un exploit exitoso podría permitir al atacante terminar el proceso de escaneo.

04 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-04 18:16

Updated : 2026-06-17 10:16


NVD link : CVE-2026-20031

Mitre link : CVE-2026-20031

CVE.ORG link : CVE-2026-20031


JSON object : View

Products Affected

No product.

CWE
CWE-248

Uncaught Exception