CVE-2019-25586

Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the URL field. Attackers can paste a buffer of 5000 characters into the 'From URL' field during torrent addition to trigger an application crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:deluge-torrent:deluge:1.3.15:*:*:*:*:*:*:*

History

17 Jun 2026, 02:32

Type Values Removed Values Added
Summary
  • (es) Deluge 1.3.15 contiene una vulnerabilidad de denegación de servicio que permite a atacantes locales bloquear la aplicación al introducir una cadena excesivamente larga en el campo URL. Los atacantes pueden pegar un búfer de 5000 caracteres en el campo 'Desde URL' durante la adición de un torrent para provocar un bloqueo de la aplicación.

24 Mar 2026, 14:41

Type Values Removed Values Added
CPE cpe:2.3:a:deluge-torrent:deluge:1.3.15:*:*:*:*:*:*:*
First Time Deluge-torrent deluge
Deluge-torrent
References () http://download.deluge-torrent.org/windows/deluge-1.3.15-win32-py2.7.exe - () http://download.deluge-torrent.org/windows/deluge-1.3.15-win32-py2.7.exe - Product
References () https://dev.deluge-torrent.org/ - () https://dev.deluge-torrent.org/ - Product
References () https://www.exploit-db.com/exploits/46883 - () https://www.exploit-db.com/exploits/46883 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/deluge-denial-of-service-via-url-field - () https://www.vulncheck.com/advisories/deluge-denial-of-service-via-url-field - Third Party Advisory

22 Mar 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-22 01:16

Updated : 2026-06-17 02:32


NVD link : CVE-2019-25586

Mitre link : CVE-2019-25586

CVE.ORG link : CVE-2019-25586


JSON object : View

Products Affected

deluge-torrent

  • deluge
CWE
CWE-466

Return of Pointer Value Outside of Expected Range