Allocation of Resources Without Limits or Throttling in ClamAV - CVE-2026-20348
Published: August 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper size handling in the XAR parser when decompressing a malformed table of contents. A remote attacker can provide a crafted XAR archive to cause a denial of service.
The issue can request an excessive allocation or exceed scan limits.