gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, dataLen) before checking the remaining buffer, allowing remote unauthenticated denial of service through excessive memory allocation and CPU or garbage collection pressure. This issue is fixed in version 0.145.1.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-whmm-qj9r-wvr2 | td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 29 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gotd
Gotd td |
|
| Vendors & Products |
Gotd
Gotd td |
|
| Metrics |
ssvc
|
Tue, 28 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, dataLen) before checking the remaining buffer, allowing remote unauthenticated denial of service through excessive memory allocation and CPU or garbage collection pressure. This issue is fixed in version 0.145.1. | |
| Title | td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode | |
| Weaknesses | CWE-770 CWE-789 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-29T14:20:26.682Z
Reserved: 2026-06-15T20:07:02.186Z
Link: CVE-2026-54638
Updated: 2026-07-29T14:20:22.827Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T15:10:31Z
Github GHSA