Telegram Desktop 2.9.2 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized message payload. Attackers can generate a 9 million byte buffer and paste it into the messaging interface to trigger an application crash.
References
| Link | Resource |
|---|---|
| https://telegram.org | Product |
| https://www.exploit-db.com/exploits/50247 | Exploit |
| https://www.vulncheck.com/advisories/telegram-desktop-denial-of-service-poc | Third Party Advisory |
| https://www.exploit-db.com/exploits/50247 | Exploit |
Configurations
History
30 Jan 2026, 00:56
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Telegram telegram Desktop
Telegram |
|
| References | () https://telegram.org - Product | |
| References | () https://www.exploit-db.com/exploits/50247 - Exploit | |
| References | () https://www.vulncheck.com/advisories/telegram-desktop-denial-of-service-poc - Third Party Advisory | |
| CPE | cpe:2.3:a:telegram:telegram_desktop:2.9.2:*:*:*:*:*:*:* |
16 Jan 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/50247 - |
16 Jan 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-16 00:16
Updated : 2026-01-30 00:56
NVD link : CVE-2021-47793
Mitre link : CVE-2021-47793
CVE.ORG link : CVE-2021-47793
JSON object : View
Products Affected
telegram
- telegram_desktop
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
