Description
An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component
Published: 2026-08-26
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An exploit in TokTok qTox version 1.18.4 permits a local attacker to trigger a denial of service by manipulating the src/persistence/serialize.cpp component. The vulnerability arises from improper handling of serialized data, leading to an application crash or halt when malformed input is processed. As a result, legitimate users experience loss of service continuity, though no remote code execution or data disclosure is reported.

Affected Systems

TokTok qTox v1.18.4 remains vulnerable to this local denial of service issue. No other versions are explicitly listed as affected, and no CNAs provide a formal impact statement or a list of affected releases beyond this single version.

Risk and Exploitability

The vulnerability can be exploited locally; the attacker must have access to the victim’s system to supply malicious data to the serialization subsystem. Due to the lack of publicly available EPSS data, the exact likelihood of exploitation remains unquantified. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation incidents. Nonetheless, its potential to disrupt service for any user with local access makes it a high‑risk denial of service that warrants swift mitigation.

Generated by OpenCVE AI on August 26, 2026 at 19:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest stable release of TokTok qTox that removes the serialization flaw
  • Apply the specific patch from the TokTok qTox repository (see the issue referenced) if an upgrade path is unavailable
  • Restart the application or service after applying the fix to ensure the changes take effect

Generated by OpenCVE AI on August 26, 2026 at 19:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Local denial of service vulnerability in TokTok qTox serialization component
Weaknesses CWE-674

Wed, 26 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-26T18:35:57.764Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-51106

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T19:16:50.800

Modified: 2026-08-26T19:16:50.800

Link: CVE-2026-51106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:00:11Z

Weaknesses