Libtorrent is a widely embedded peer-to-peer networking library used across torrent clients and applications, and its narrow product scope belies a significant downstream footprint. The observed vulnerability surface centers on input-handling weaknesses such as improper input validation and out-of-bounds reads, reflecting the parsing and protocol-state complexity inherent to a peer-to-peer implementation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libtorrent over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-7164HIGH The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segmentation fault and crash) via a crafted GZIP response. | Feb 7, 2017 | 7.5 | 22 | NO | NO |
CVE-2017-9847MEDIUM The bdecode function in bdecode.cpp in libtorrent 1.1.3 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. | Jun 24, 2017 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libtorrent.
Media articles that mention a CVE ID that affects a product developed by Libtorrent — matched by CVE ID, not by vendor name.