CVE-2026-20337
Received Received - Intake

Denial of Service in ClamAV Zip Archive Parser

Vulnerability report for CVE-2026-20337, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
clamav clamav *
cisco secure_endpoint_connector *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in ClamAV's zip archive parser. It allows an unauthenticated remote attacker to cause a denial of service (DoS) by submitting a crafted zip file. The issue stems from improper boundary checks during scanning, which can lead to an out-of-bounds write condition, crashing the ClamAV scanning process.

Detection Guidance

Monitor ClamAV scanning processes for crashes or unexpected terminations when processing zip files. Check logs for out-of-bounds write errors or DoS conditions during scans. Use network traffic analysis tools to detect unusual zip file submissions to ClamAV services.

Impact Analysis

If exploited, this vulnerability could disrupt ClamAV scanning operations on affected devices. This may lead to system instability or downtime, particularly if the scanning process operates with high privileges, such as on Windows-based platforms.

Compliance Impact

This vulnerability primarily causes a denial of service (DoS) by crashing the ClamAV scanning process, which could disrupt malware scanning operations. While not directly violating GDPR or HIPAA, a DoS condition might impair security monitoring, potentially leading to non-compliance if it prevents timely detection of threats or data breaches.

Mitigation Strategies

Apply the latest ClamAV software updates provided by Cisco to patch the vulnerability. Disable automatic scanning of zip files if possible until patched. Restrict access to ClamAV scanning services to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20337. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart