CVE-2026-57080Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framing in _process_messages trusts the 4-byte length prefix sent by a connected peer with no upper bound, while receive_data appends every inbound byte to the input buffer. A peer announces a length prefix of up to about 4 GiB and then streams bytes; the decoder waits until the buffer holds the full message before processing it, so the buffer grows without limit. Peer connections are unauthenticated, so any peer in the swarm exhausts the downloading process's memory. The largest legitimate message is a 16 KiB piece block, so any announced length far above that is anomalous.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-30); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-20: 1Patch / Workaround · 2026-07-20: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-20: 106-3007-20
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-302
Disclosure2
2026-07-201
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    #CVE-2026-57080 (CVSS 7.5 HIGH) affects Net::BitTorrent ≤2.1.0 for Perl. Remote attackers can exhaust memory via uncapped peer-wire message-length prefix. Unauthenticated exploitation possible. Patch immediately. #CVE #PatchNow https://t.co/CNpsUbhsr9

    Post summary

    CVE‑2026‑57080 in Net::BitTorrent can lead to memory exhaustion; immediate patching is required, but no PoC or active exploitation evidence is presented.

    0000033
    88 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-57080 Net::BitTorrent versions through 2.0.1 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framing in _process_mes… https://www.cve.org/CVERecord?id=CVE-2026-57080 ----- Traducción: CVE-2026-57080 Net… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-57080 for Net::BitTorrent, detailing a remote memory exhaustion flaw caused by an uncapped peer‑wire message-length prefix.

    0000025
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-57080 Net::BitTorrent versions through 2.0.1 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framing in _process_mes… https://www.cve.org/CVERecord?id=CVE-2026-57080

    Post summary

    The post announces CVE‑2026‑57080, describing a remote memory exhaustion flaw in Net::BitTorrent for Perl, but offers no exploit code, patch, or evidence of active exploitation.

    00000721
    57.7K followersView on X

Explore more