KeePass Official Homepageproduct
https://keepass.info/ CVE-2020-37178
MEDIUM
KeePass 2.44 - Denial of Service (PoC)
Record summary
CVE-2020-37178 has a selected CVSS score of 4.6 (medium); EIP currently links 1 catalogued exploit.
Description
KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dragging and dropping malicious HTML files into the help area, potentially causing application instability or crash.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
KeePass Password SafeBrowse Keepass / KeePass Password Safe | CVE List | < 2.44 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBKeePass 2.44 - Denial of Service (PoC)ExploitDB exploitby Mustafa Emre GülNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37178 ExploitDB-47952exploit
https://www.exploit-db.com/exploits/47952 VulnCheck Advisory: KeePass 2.44 - Denial of Service (PoC)Third-party advisory
https://www.vulncheck.com/advisories/keepass-denial-of-service-poc