Denial of Service Flaw in Gotd/Td Telegram MTProto API Client
CVE-2026-54638
7.5HIGH
What is CVE-2026-54638?
The Gotd/Td Telegram MTProto API client prior to version 0.145.1 contains a vulnerability that allows for remote unauthenticated denial of service. The issue arises from the proto.UnencryptedMessage.Decode function, which reads an attacker-controlled data length from an unauthenticated MTProto unencrypted packet. This results in excessive memory allocation and substantial CPU or garbage collection pressure, thereby impacting system performance. The vulnerability has been addressed in version 0.145.1.
Affected Version(s)
td < 0.145.1
