Telegram Desktop Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Telegram Desktop version 2.9.2. This issue allows attackers to crash the application by sending an oversized message payload. By generating a buffer of 9 million bytes and pasting it into the messaging interface, the application can be forced to crash.

Impact

Exploiting this vulnerability leads to a crash of the Telegram Desktop application, causing a denial-of-service condition where the application becomes unresponsive or unavailable.

Reproduction

To reproduce this vulnerability, create a text file containing 9 million bytes of data. This can be done using a simple script that generates a buffer of the desired size. Once the file is created, open Telegram Desktop and navigate to 'Saved Messages'. Copy the contents of the file and paste it into the message input area. The application will crash shortly after.

Added: Jan 16, 2026, 12:44 AM
Updated: Jan 16, 2026, 12:44 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
4.6
remediation
0.0
relevance
2.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.