Description
Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input.

bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining buffer by value while the list and dictionary branches capture the whole remainder, so every live recursion frame keeps its own copy of the shrinking buffer (O(N^2) bytes for an N-deep input). The decoder runs on every untrusted bencode source: .torrent files, BEP09 metadata fetched from peers, DHT messages, and tracker responses.

A bencoded input of roughly 150,000 nested lists (about 150 KB on the wire) drives multi-gigabyte peak memory, so one short message from any peer, or one crafted .torrent file or magnet link, terminates the client.
Published: 2026-06-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. The bdecode routine recurses once for each list or dictionary without a depth limit and passes the remaining buffer by value to each recursive call while the branches hold the entire remainder. Consequently, each active stack frame retains its own copy of the shrinking input, leading to quadratic memory growth (O(N²)). A payload with roughly 150 000 nested lists—about 150 KB on the wire—drives peak memory usage into multiple gigabytes, causing the client to crash or become unusable. This demonstrates uncontrolled resource consumption (CWE‑400) and uncontrolled recursion (CWE‑674).

Affected Systems

All releases of SANKO Net::BitTorrent prior to version 2.1.0 are affected. The decoder operates on every untrusted bencode source—including .torrent files, BEP09 metadata fetched from peers, DHT messages, and tracker responses—so any client incorporating this module is vulnerable unless it has been upgraded to version 2.1.0 or later.

Risk and Exploitability

The flaw is a classic remote memory exhaustion vulnerability. The decoder operates on any untrusted bencoded input, allowing an attacker to trigger it by sending a single deeply nested payload from any peer, or by delivering a crafted .torrent file or magnet link. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 7.5 confirms a high severity. Because the chunk of data that can be tricked into generating large memory usage is small, the risk remains high until the client is patched or mitigated.

Generated by OpenCVE AI on July 31, 2026 at 16:38 UTC.

Remediation

Vendor Solution

Upgrade to version 2.1.0 or later.


OpenCVE Recommended Actions

  • Upgrade SANKO Net::BitTorrent to version 2.1.0 or later to apply the vendor-provided fix.
  • Configure the bdecode routine to enforce a maximum nesting depth of approximately 100 levels before decoding any bencoded data.
  • Pre‑validate every incoming .torrent file, BEP09 metadata, DHT message, and tracker response; reject or truncate any payload that exceeds the established depth limit before passing it to the decoder.
  • Monitor SANKO Net::BitTorrent security advisories and upgrade to subsequent patched releases as they become available.

Generated by OpenCVE AI on July 31, 2026 at 16:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Description Net::BitTorrent versions through 2.0.1 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining buffer by value while the list and dictionary branches capture the whole remainder, so every live recursion frame keeps its own copy of the shrinking buffer (O(N^2) bytes for an N-deep input). The decoder runs on every untrusted bencode source: .torrent files, BEP09 metadata fetched from peers, DHT messages, and tracker responses. A bencoded input of roughly 150,000 nested lists (about 150 KB on the wire) drives multi-gigabyte peak memory, so one short message from any peer, or one crafted .torrent file or magnet link, terminates the client. Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining buffer by value while the list and dictionary branches capture the whole remainder, so every live recursion frame keeps its own copy of the shrinking buffer (O(N^2) bytes for an N-deep input). The decoder runs on every untrusted bencode source: .torrent files, BEP09 metadata fetched from peers, DHT messages, and tracker responses. A bencoded input of roughly 150,000 nested lists (about 150 KB on the wire) drives multi-gigabyte peak memory, so one short message from any peer, or one crafted .torrent file or magnet link, terminates the client.
Title Net::BitTorrent versions through 2.0.1 for Perl allow remote memory exhaustion via deeply nested bencoded input Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input
References

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Sanko
Sanko net::bittorrent
Vendors & Products Sanko
Sanko net::bittorrent

Tue, 30 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 11:45:00 +0000

Type Values Removed Values Added
Description Net::BitTorrent versions through 2.0.1 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining buffer by value while the list and dictionary branches capture the whole remainder, so every live recursion frame keeps its own copy of the shrinking buffer (O(N^2) bytes for an N-deep input). The decoder runs on every untrusted bencode source: .torrent files, BEP09 metadata fetched from peers, DHT messages, and tracker responses. A bencoded input of roughly 150,000 nested lists (about 150 KB on the wire) drives multi-gigabyte peak memory, so one short message from any peer, or one crafted .torrent file or magnet link, terminates the client.
Title Net::BitTorrent versions through 2.0.1 for Perl allow remote memory exhaustion via deeply nested bencoded input
Weaknesses CWE-400
CWE-674
References

Subscriptions

Sanko Net::bittorrent
cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2026-07-20T06:42:53.260Z

Reserved: 2026-06-23T18:20:33.514Z

Link: CVE-2026-57081

cve-icon Vulnrichment

Updated: 2026-06-30T15:04:00.752Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:45:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-674

    Uncontrolled Recursion