Security Advisory

CVE-2026-54638

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-28 22:14:53
Last updated 2026-07-29 14:20:26
Assigner GitHub_M
CVSS score not scored
State PUBLISHED

Description

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, dataLen) before checking the remaining buffer, allowing remote unauthenticated denial of service through excessive memory allocation and CPU or garbage collection pressure. This issue is fixed in version 0.145.1.