CVE-2026-57081Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining buffer by value while the list and dictionary branches capture the whole remainder, so every live recursion frame keeps its own copy of the shrinking buffer (O(N^2) bytes for an N-deep input). The decoder runs on every untrusted bencode source: .torrent files, BEP09 metadata fetched from peers, DHT messages, and tracker responses. A bencoded input of roughly 150,000 nested lists (about 150 KB on the wire) drives multi-gigabyte peak memory, so one short message from any peer, or one crafted .torrent file or magnet link, terminates the client.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-30); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-20: 1Patch / Workaround · 2026-07-20: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-20: 106-3007-20
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-302
Disclosure2
2026-07-201
Disclosure1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH: CVE-2026-57081 (CVSS 7.5) Net::BitTorrent ≤2.1.0 for Perl vulnerable to remote memory exhaustion via nested bencoded input. 150KB payload → multi-GB memory use = DoS. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/nyeAMMrL64

    Post summary

    A newly identified high‑severity vulnerability (CVE‑2026‑57081) in Net::BitTorrent allows remote memory exhaustion—payloads of 150 KB can consume multi‑gigabyte memory—leading to a DoS. Prompt patching is strongly recommended.

    0000045
    88 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-57081 Net::BitTorrent versions through 2.0.1 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary … https://www.cve.org/CVERecord?id=CVE-2026-57081 ----- Traducción: CVE-2026-57081 Net… http://infoflow.cloud`

    Post summary

    The tweet discloses details of CVE‑2026‑57081— a memory‑exhaustion flaw in Net::BitTorrent for Perl caused by deeply nested bencoded inputs, with a link to the official CVE record.

    0000025
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-57081 Net::BitTorrent versions through 2.0.1 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary … https://www.cve.org/CVERecord?id=CVE-2026-57081

    Post summary

    CVE-2026-57081 exposes Net::BitTorrent up to 2.0.1 to remote memory exhaustion via deeply nested bencoded input; no exploits, PoC, or mitigation details are included.

    00000689
    57.7K followersView on X

Explore more