Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Telegram

First CVE: Mar 14, 2017Active for: 9 yearsTotal CVEs: 37
22.2
VTI Score
Low

Telegram's vulnerability footprint, though modest in volume relative to major platform vendors, reflects the prominence of its messaging and voice-communication applications across consumer and enterprise deployments. The exposure spans its desktop, mobile, and web clients and centers on weakness classes including out-of-bounds writes, sensitive-information leakage, type confusion, and cleartext storage—issues that recur in real-time communication software where protocol handling, encryption implementation, and state management are security-critical. A meaningful share of the vendor's disclosures reach serious severity, reflecting the sensitivity of user data and the authentication layers these products protect. Defenders should prioritize updates to end-user clients and monitor for protocol-layer flaws; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
37
Total CVEs
More Total CVEs than 98% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Telegram over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2017
9 years ago
Most Recent CVE
Jan 16, 2026
189 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-40532CRITICAL
Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.
Sep 6, 20219.831NONO
CVE-2018-17613CRITICAL
Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKS5 protocol.
Sep 28, 20189.830NONO
CVE-2019-10044HIGH
Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attack when displaying messages containing U
Mar 25, 20198.828NONO
CVE-2017-17715HIGH
The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal via a pathname obtained in a file-transfe
Dec 16, 20178.828NONO
CVE-2024-7014HIGH
EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.
Jul 23, 20248.127NONO
CVE-2018-20436HIGH
The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composing a chat message, before that
Dec 24, 20188.126NONO
CVE-2020-17448HIGH
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filena
Aug 11, 20207.825NONO
CVE-2018-17780MEDIUM
Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because of an unsafe default behavior in
Sep 29, 20186.524NONO
CVE-2023-26818MEDIUM
Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag.
May 19, 20235.523NONO
CVE-2018-17231HIGH
Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "Edit color palette" search that triggers
Sep 19, 20187.523NONO
View all 37 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products37 CVEs
62%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local15 (40.5%)
Network18 (48.6%)
Unknown0 (0.0%)
Physical4 (10.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (94.6%)
High2 (5.4%)
Unknown0 (0.0%)
User Interaction
None21 (56.8%)
Unknown0 (0.0%)
Required16 (43.2%)
Privileges Required
Low8 (21.6%)
High0 (0.0%)
None29 (78.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Telegram.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Telegram — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Telegram's Products

View all 4 CNAs →

Top CWEs