CVE-2026-20031
Description
A flaw was found in the HTML Cascading Style Sheets (CSS) module of ClamAV. An attacker could exploit this vulnerability by submitting a specially crafted HTML file for scanning. This flaw is due to improper error handling when splitting UTF-8 strings that could lead to a denial of service (DoS) condition, terminating the scanning process on the affected device.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Understanding the Weakness (CWE)
Availability,Confidentiality
Technical Impact: DoS: Crash, Exit, or Restart; Read Application Data
An uncaught exception could cause the system to be placed in a state that could lead to a crash, exposure of sensitive information or other unintended behaviors.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.