Secure Endpoint and ClamAV
CVE-2024-20380: ClamAV HTML Parser Denial of Service Vulnerability
A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| ClamAV 1.3 | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to an issue in the C to Rust foreign function interface. An attacker could exploit this vulnerability by submitting a crafted file containing HTML content to be scanned by ClamAV on an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 11 Oct 2026.