CVE-2026-20338
published 2026-08-07CVE-2026-20338: A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.33%
25.7th percentile
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.
Affected
146 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
| cisco | cisco_secure_endpoint | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco ClamAV up to 8.4.5.30483 Zip Archive Parser double free
vuldb·2026-08-07·CVSS 7.5
CVE-2026-20338 [HIGH] Cisco ClamAV up to 8.4.5.30483 Zip Archive Parser double free
A vulnerability described as critical has been identified in Cisco ClamAV. The impacted element is an unknown function of the component Zip Archive Parser. The manipulation results in double free.
This vulnerability is reported as CVE-2026-20338. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
GHSA
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
ghsa_unreviewed·2026-08-07
CVE-2026-20338 [HIGH] CWE-415 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.
No detection rules found.
No public exploits indexed.
2026-08-07
Published