Bitmessage is a decentralized peer-to-peer messaging application focused on anonymity and censorship resistance; its vulnerability footprint centers on the PyBitmessage reference implementation. The durable signal in its disclosure history reflects the complexity of code-generation and message-handling logic, with observed weakness classes including code injection and insufficient information placeholders characteristic of evolving research-stage cryptographic software; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bitmessage over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000070HIGH Bitmessage PyBitmessage version v0.6.2 (and introduced in or after commit 8ce72d8d2d25973b7064b1cf76a6b0b3d62f0ba0) contains a Eval injection vulnerability in main program, file sr | Mar 13, 2018 | 8.8 | 26 | NO | NO |
CVE-2021-26917MEDIUM PyBitmessage through 0.6.3.2 allows attackers to write screen captures to Potentially Unwanted Directories via a crafted apinotifypath value. NOTE: the discoverer states "security | Feb 8, 2021 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bitmessage.
Media articles that mention a CVE ID that affects a product developed by Bitmessage — matched by CVE ID, not by vendor name.