CVE-2026-57080: Net::BitTorrent versions through 2.0.1 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix Robert Rothenberg 30 Jun 2026 11:07 UTC

========================================================================
CVE-2026-57080                                       CPAN Security Group
========================================================================

         CVE ID:  CVE-2026-57080
   Distribution:  Net-BitTorrent
       Versions:  through 2.0.1

       MetaCPAN:  https://metacpan.org/dist/Net-BitTorrent
       VCS Repo:  https://github.com/sanko/Net-BitTorrent.pm

Net::BitTorrent versions through 2.0.1 for Perl allow remote memory
exhaustion via an uncapped peer-wire message-length prefix

Description
-----------
Net::BitTorrent versions through 2.0.1 for Perl allow remote memory
exhaustion via an uncapped peer-wire message-length prefix.

The peer-wire framing in _process_messages trusts the 4-byte length
prefix sent by a connected peer with no upper bound, while receive_data
appends every inbound byte to the input buffer. A peer announces a
length prefix of up to about 4 GiB and then streams bytes; the decoder
waits until the buffer holds the full message before processing it, so
the buffer grows without limit.

Peer connections are unauthenticated, so any peer in the swarm exhausts
the downloading process's memory. The largest legitimate message is a
16 KiB piece block, so any announced length far above that is
anomalous.

Problem types
-------------
- CWE-770 Allocation of Resources Without Limits or Throttling
- CWE-400 Uncontrolled Resource Consumption

Workarounds
-----------
There is no fixed release. Reject a peer-wire message length above a
sane maximum (well above the 16 KiB largest legitimate message) and
disconnect the peer instead of buffering unboundedly.

References
----------
https://github.com/sanko/Net-BitTorrent.pm/security/advisories/GHSA-7jr6-2jf4-6qc4