What is CVE-2026-20346?
This vulnerability exists in the PDF file format parser of ClamAV. An unauthenticated remote attacker could exploit this via a crafted PDF file to trigger memory corruption, potentially leading to a denial-of-service (DoS) condition or other expanded impacts. Users are advised to update ClamAV to the latest version.
Azərbaycanca: Bu zəiflik ClamAV antivirus skanerinin PDF fayl analizatorunda aşkar edilib. Uzaqdan autentifikasiya olunmamış hücumçu xüsusi hazırlanmış PDF fayl vasitəsilə memory corruption yaradaraq xidmət dayandırma (DoS) vəziyyətinə səbəb ola bilər. Dəqiq təsir azaldılmasa da, istifadəçilərə ClamAV-ı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: ClamAV
FAQ2
In which software was CVE-2026-20346 discovered?
This vulnerability exists in the PDF file format parser of the ClamAV antivirus scanner.
Does CVE-2026-20346 require authentication for a remote attack?
No, an unauthenticated remote attacker could exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.