CVE-2020-37178: KeePass 2.44 - Denial of Service (PoC)
Published Feb 11, 2026
·Updated
KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dragging and dropping malicious HTML files into the help area, potentially causing application instability or crash.
Affected Software
1 affected component
KeePass KeePass Password Safe<2.44
Event History
Feb 11, 2026
CVE Published
via MITRE·08:37 PM
Data Sourced
via MITRE·08:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-37178?
The severity of CVE-2020-37178 is classified as high with a score of 7.5.
2
How does CVE-2020-37178 affect KeePass?
CVE-2020-37178 affects KeePass by allowing attackers to trigger a denial of service through malicious HTML files.
3
What versions of KeePass are affected by CVE-2020-37178?
All versions of KeePass Password Safe prior to 2.44 are affected by CVE-2020-37178.
4
How can I mitigate the effects of CVE-2020-37178?
Mitigation for CVE-2020-37178 includes upgrading to KeePass version 2.44 or later.
5
Is CVE-2020-37178 a critical vulnerability?
CVE-2020-37178 is considered critical due to its potential for causing application instability or crashes.