CVE-2020-37178Disclosure

LOWCVSS 4.6 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dragging and dropping malicious HTML files into the help area, potentially causing application instability or crash.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-12)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-11: 1Mentions · 2026-02-12: 2PoC Mentioned / Linked · 2026-02-12: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 102-1102-12
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-111
Disclosure1
2026-02-122
General1Patch1
Full discourse3 posts
  • CCB Alert@CCBalert
    Patch

    Warning: High Code Injection in #Keepass. CVE-2020-37178 CVSS: 7.5. A remote attacker can cause app crash without privileges. There is a publicly available exploit. Update to 2.44 or later. #Patch #Patch #Patch

    Post summary

    CVE-2020-37178 is a code injection flaw in KeePass that can crash the app without privileges; a publicly available exploit exists, and users should update to version 2.44 or newer.

    00001296
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2020-37178 KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dr… https://www.cve.org/CVERecord?id=CVE-2020-37178

    Post summary

    The post announces a denial‑of‑service vulnerability in KeePass Password Safe’s HTML handling for versions prior to 2.44, providing basic technical details but no PoC, exploit code, or patch information.

    00010171
    56.5K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2020-37178 - Keepass - KeePass Password Safe - https://www.redpacketsecurity.com/cve-alert-cve-2020-37178-keepass-keepass-password-safe/ #OSINT #ThreatIntel #CyberSecurity #cve-2020-37178 #keepass #keepass-password-safe

    Post summary

    The tweet merely announces the existence of CVE-2020-37178 and provides a link to an alert page, offering no further details on exploitation, patching, or technical aspects.

    00000111
    3.5K followersView on X

Explore more