# CVE-2021-26948

## Summary

- **CVE ID:** CVE-2021-26948
- **Severity:** UNKNOWN
- **CVSS Score:** 0.01
- **CWE:** CWE-479
- **Published:** Mar 3, 2022
- **Last Modified:** Mar 13, 2026

## Description

Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file.

## Affected Products

- n/a — htmldoc (v1.9.11)

## References

- [CNA](https://github.com/michaelrsweet/htmldoc/issues/410)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 33.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._