CVE-2026-20338: ClamAV Zip Archive Parser Denial of Service Vulnerability
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning, potentially causing the ClamAV scanning process to terminate. Cisco Secure Endpoint and ClamAV are affected, with multiple versions impacted.