Telegram Desktop
Vendor:
First CVE: Sep 19, 2018 · Active for 7 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Telegram Desktop over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 19, 2018
7 years ago
Most Recent CVE
Jan 16, 2026
189 days ago
CVE Severity & Scoring
Telegram Desktop9 CVEs
11%
33%
44%
11%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (11.1%)
Network7 (77.8%)
Unknown0 (0.0%)
Physical1 (11.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None8 (88.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17613CRITICAL Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKS5 protocol. | Sep 28, 2018 | 9.8 | 30 | NO | NO |
CVE-2019-10044HIGH Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attack when displaying messages containing U | Mar 25, 2019 | 8.8 | 28 | NO | NO |
CVE-2020-17448HIGH Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filena | Aug 11, 2020 | 7.8 | 25 | NO | NO |
CVE-2018-17780MEDIUM Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because of an unsafe default behavior in | Sep 29, 2018 | 6.5 | 24 | NO | NO |
CVE-2018-17231HIGH Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "Edit color palette" search that triggers | Sep 19, 2018 | 7.5 | 23 | NO | NO |
CVE-2021-47793HIGH Telegram Desktop 2.9.2 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized message payload. Attackers can generate a 9 | Jan 16, 2026 | 7.5 | 22 | NO | NO |
CVE-2021-36769MEDIUM A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop before 2.8.8. An attacker can cause the server to receive messag | Jul 17, 2021 | 5.3 | 20 | NO | NO |
CVE-2020-12474MEDIUM Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public URL or a group chat in | May 1, 2020 | 6.5 | 19 | NO | NO |
Telegram Desktop through 2.4.3 does not require passcode entry upon pushing the Export key within the Export Telegram Data wizard. The threat model is a victim who has voluntarily | Oct 14, 2020 | 2.4 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Telegram Desktop
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.9.2 | 1 | 7.5 | 0.4% | 0 | 0 |
| 1.3.16 | 1 | 9.8 | 1.6% | 0 | 0 |
| 1.3.14 | 2 | 7.0 | 1.7% | 0 | 0 |