KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dragging and dropping malicious HTML files into the help area, potentially causing application instability or crash.
History

Fri, 13 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 12 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Keepass
Keepass password Safe
Vendors & Products Keepass
Keepass password Safe

Wed, 11 Feb 2026 21:00:00 +0000

Type Values Removed Values Added
Description KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dragging and dropping malicious HTML files into the help area, potentially causing application instability or crash.
Title KeePass 2.44 - Denial of Service (PoC)
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-13T17:12:23.609Z

Reserved: 2026-02-10T18:30:18.387Z

Link: CVE-2020-37178

cve-icon Vulnrichment

Updated: 2026-02-13T17:12:20.319Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-11T21:16:10.953

Modified: 2026-02-12T15:10:37.307

Link: CVE-2020-37178

cve-icon Redhat

Severity : Important

Publid Date: 2026-02-11T20:37:01Z

Links: CVE-2020-37178 - Bugzilla