PT-2026-26951 · Deluge · Deluge

Victor Mondragón

·

Published

2026-03-22

·

Updated

2026-03-22

·

CVE-2019-25585

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Deluge version 1.3.15
Description A denial of service issue exists in Deluge that allows local attackers to crash the application. This occurs by providing an excessively long string, specifically a 5000-byte buffer, in the Webseeds field during torrent creation. The application crashes when processing this oversized input.
Recommendations Update to a newer version of Deluge that addresses this issue. As a temporary workaround, limit the length of the input allowed in the Webseeds field during torrent creation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2019-25585
PYSEC-2026-38

Affected Products

Deluge