CVE-2026-20031

Publication date 4 March 2026

Last updated 27 April 2026


Ubuntu priority

Cvss 3 Severity Score

5.3 · Medium

Score breakdown

Description

A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when splitting UTF-8 strings. An attacker could exploit this vulnerability by submitting a crafted HTML file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the scanning process.

Read the notes from the security team

Status

Package Ubuntu Release Status
clamav 26.04 LTS resolute
Fixed 1.4.4+dfsg-0ubuntu0.26.04.1
25.10 questing
Fixed 1.4.4+dfsg-0ubuntu0.25.10.1
24.04 LTS noble
Fixed 1.4.4+dfsg-0ubuntu0.24.04.1
22.04 LTS jammy
Fixed 1.4.4+dfsg-0ubuntu0.22.04.1
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty
Needs evaluation

Notes


leosilva

Building ClamAV requires rust compiler >= 1.61 releases as bionic, xenial and trusty are not covered by that version of rustc. ClamAV new versions can't build in these releases anymore.

Severity score breakdown

CVSS version: CVSS v3.0

Base score 5.3 · Medium

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L


Access our resources on patching vulnerabilities