Denial of Service Flaw in Gotd/Td Telegram MTProto API Client
CVE-2026-54638

7.5HIGH

Key Information:

Vendor

Gotd

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-54638?

The Gotd/Td Telegram MTProto API client prior to version 0.145.1 contains a vulnerability that allows for remote unauthenticated denial of service. The issue arises from the proto.UnencryptedMessage.Decode function, which reads an attacker-controlled data length from an unauthenticated MTProto unencrypted packet. This results in excessive memory allocation and substantial CPU or garbage collection pressure, thereby impacting system performance. The vulnerability has been addressed in version 0.145.1.

Affected Version(s)

td < 0.145.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.