What is CVE-2026-54638?
In gotd/td versions prior to 0.145.1, an unauthenticated MTProto packet can trigger excessive memory allocation by using an attacker-controlled `dataLen` without proper buffer bounds checking, leading to resource exhaustion and potential Denial of Service (DoS). Users should upgrade to version 0.145.1 immediately.
Azərbaycanca: gotd/td Go kitabxanasının 0.145.1-dən əvvəlki versiyalarında autentifikasiya olunmamış MTProto paketlərində `dataLen` parametrinin yoxlanılmadan birbaşa istifadəsi nəticəsində yaddaşın həddindən artıq istehlakı (resource exhaustion) baş verə bilər. Bu zəiflik uzaqdan hücumçuya xidmətin işini dayandırmağa (DoS) imkan verir, ona görə də dərhal 0.145.1 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which versions of the gotd/td library are affected by CVE-2026-54638?
This vulnerability affects versions of the gotd/td library prior to 0.145.1. Users are advised to upgrade to version 0.145.1 immediately.
What outcome can an attacker achieve by exploiting CVE-2026-54638?
A remote, unauthenticated attacker can trigger excessive memory allocation by manipulating the `dataLen` parameter, leading to resource exhaustion and a potential Denial of Service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.