deluge
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting delugepage 1 of 1
- CVE-2019-25585MEDIUMCVSS 5.5EG 6.22026-03-22
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Webseeds field. Attackers can paste a buffer of 5000 bytes into the Webseeds field…
- CVE-2019-25586MEDIUMCVSS 5.5EG 6.22026-03-22
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the URL field. Attackers can paste a buffer of 5000 characters into the 'From URL' fie…
- CVE-2021-3427MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2.1.02022-08-26
vulnerable: 2.0.0 ... 2.0.5 (8 versions)
The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute …
Check whether deluge is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for deluge CVEs against the assets you own.
Start Free Scan →