CVE-2026-20031
Clam AntiVirus vulnerability analysis and mitigation

Overview

CVE-2026-20031 is a denial-of-service (DoS) vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV, affecting Cisco Secure Endpoint Connector for Linux, Mac, and Windows, as well as Cisco Secure Endpoint Private Cloud. The flaw stems from improper error handling when splitting UTF-8 strings, allowing an unauthenticated remote attacker to terminate the ClamAV scanning process by submitting a crafted HTML file. It was discovered during internal Cisco security testing and publicly disclosed on March 4, 2026. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Cisco Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-248 (Uncaught Exception), arising from improper error handling in ClamAV's HTML CSS parsing module when processing UTF-8 string splitting operations. An attacker exploits this by submitting a specially crafted HTML file to any service or endpoint that passes files to ClamAV for scanning — no authentication or user interaction is required. The malformed input triggers an unhandled exception that causes the ClamAV scanning process to crash. Cisco Bug IDs CSCwr70252, CSCwr70255, CSCwr70257, and CSCwr70268 track the issue across affected platforms (Cisco Advisory).

Impact

Successful exploitation causes the ClamAV scanning process to crash, disrupting or halting antivirus scanning operations on the affected device. The impact is limited to availability — there is no confidentiality or integrity impact, and overall system stability is not affected. However, a crashed scanning process could delay or prevent detection of malware, potentially creating a window for other threats to go undetected on endpoints running Cisco Secure Endpoint Connector (Cisco Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported. Cisco PSIRT confirmed it is not aware of any public announcements or malicious use of this vulnerability at the time of disclosure. The EPSS score is approximately 0.094%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Cisco Advisory, Feedly).

Exploitation steps

  1. Identify target: Locate a system running a vulnerable version of Cisco Secure Endpoint Connector (Linux prior to 1.28.1, Mac prior to 1.27.2, Windows prior to 8.6.0) or any service that passes user-submitted files to ClamAV for scanning.
  2. Craft malicious HTML file: Construct an HTML file containing CSS content with malformed or specially crafted UTF-8 strings designed to trigger the error handling flaw during string-splitting operations in ClamAV's CSS module.
  3. Submit file for scanning: Deliver the crafted HTML file to the target system through any available vector — email attachment, web upload, file share, or direct submission to a scanning endpoint — such that ClamAV processes it.
  4. Trigger crash: ClamAV's HTML CSS module encounters the malformed UTF-8 input, fails to handle the resulting exception, and the scanning process terminates, disrupting antivirus operations (Cisco Advisory).

Indicators of compromise

  • Process: Unexpected termination or crash of the ClamAV scanning process (clamd, clamscan, or the Cisco Secure Endpoint connector scanning service) without a clear system-level cause.
  • Logs: ClamAV or Cisco Secure Endpoint logs showing scanning process crashes or restarts, particularly correlated with processing of HTML files; error messages related to UTF-8 string handling or CSS module exceptions.
  • File System: Presence of crafted HTML files with unusual or malformed CSS/UTF-8 content in directories monitored or scanned by ClamAV.
  • Network: Repeated submission of HTML files from an external or unexpected source to services that invoke ClamAV scanning, especially if followed by scanning service downtime (Cisco Advisory).

Mitigation and workarounds

Cisco has released fixed software versions addressing this vulnerability: Secure Endpoint Connector for Linux 1.28.1, Secure Endpoint Connector for Mac 1.27.2, Secure Endpoint Connector for Windows 8.6.0, and Secure Endpoint Private Cloud 4.2.7 or earlier with updated connectors. Updated connector releases are available through the Cisco Secure Endpoint portal and may be applied automatically depending on configured policy. Cisco confirms there are no workarounds available; upgrading to a fixed release is the only remediation (Cisco Advisory). Standalone ClamAV users should update to version 1.5.2 or later, as patched releases are available via the ClamAV GitHub releases. Linux distribution users (openSUSE, Ubuntu, Amazon Linux) should apply vendor-provided security updates.

Community reactions

The vulnerability received routine coverage from Linux distribution security channels, with openSUSE, Ubuntu, and Amazon Linux all issuing security advisories and package updates. Security aggregators including Tenable (Nessus plugins 302191, 311213, 311324), Qualys (761700), and VulDB tracked the issue. Coverage was largely technical and low-profile, consistent with a medium-severity DoS vulnerability with no known exploitation (Cisco Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

clamav

Affected

sid

clamav: 1.4.4+dfsg-1

Fixed

trixie

clamav

Affected

Ubuntu

Fixed

bionic (esm-infra)

clamav

Unknown

devel

clamav

Not Affected

focal (esm-infra)

clamav

Unknown

jammy

clamav: 1.4.4+dfsg-0ubuntu0.22.04.1

Fixed

noble

clamav: 1.4.4+dfsg-0ubuntu0.24.04.1

Fixed

questing

clamav: 1.4.4+dfsg-0ubuntu0.25.10.1

Fixed

resolute

clamav: 1.4.4+dfsg-0ubuntu0.26.04.1

Fixed

trusty (esm-infra-legacy)

clamav

Unknown

Alpine

Fixed

edge

clamav: 1.4.4-r0

Fixed

v3.23

clamav: 1.4.4-r0

Fixed

SourceThis report was generated using AI

Related Clam AntiVirus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20348HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav1.4-milter
NoYesAug 07, 2026
CVE-2026-20347HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav1.4-milter
NoYesAug 07, 2026
CVE-2026-20346HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav1.4
NoYesAug 07, 2026
CVE-2026-20345HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav1.5-devel
NoYesAug 07, 2026
CVE-2026-70622HIGH7.1
  • Clam AntiVirus logoClam AntiVirus
  • clamav1.5
NoNoAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management