DEBIAN-CVE-2026-7701

Source
https://security-tracker.debian.org/tracker/CVE-2026-7701
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-7701.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-7701
Upstream
  • CVE-2026-7701
Published
2026-05-03T16:15:57Z
Modified
2026-09-14T17:03:34Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. There is ongoing doubt regarding the real existence of this vulnerability. Upgrading to version 6.7.6 is able to resolve this issue. Upgrading the affected component is recommended. The vendor provides this rationale for the dispute: "[T]he described scenario does not lead to any security issue or vulnerability, and only causes a one-time crash. In the outlined scenario, the targeted user must perform an active action, which doesn't produce any consequences after the app is relaunched."

References

Affected packages

Debian:12 / telegram-desktop

Package

Name
telegram-desktop
Purl
pkg:deb/debian/telegram-desktop?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.6.5+ds-2
4.8.1+ds-1
4.8.1+ds-2~bpo11+1
4.8.1+ds-2~bpo12+1
4.8.1+ds-2
4.9.3+ds-1
4.9.7+ds-1
4.10.3+ds-1
4.10.3+ds-2
4.11.5+ds-1
4.11.8+ds-1
4.13.1+ds-1
4.14.3+ds-1
4.14.4+ds-1
4.14.9+ds-1
4.14.9+ds-1.1
5.*
5.7.2+ds-2~bpo13+1
5.7.2+ds-2
5.7.2+ds-3
5.7.2+ds-4
5.7.2+ds-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-7701.json"

Debian:14 / telegram-desktop

Package

Name
telegram-desktop
Purl
pkg:deb/debian/telegram-desktop?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.14-1
1.0.29-1
1.1.0-1
1.1.10-1
1.1.18-1
1.1.19-1
1.1.19-2
1.1.23-1~bpo9+1
1.1.23-1
1.1.23-2
1.1.23-3
1.2.1-1
1.2.1-2
1.2.6-1
1.2.6-2
1.2.15-1
1.2.17-1
1.3.7-1
1.3.10-1
1.3.10-2
1.3.14-1
1.4.0-1
1.5.2-1
1.5.4-1
1.5.8-1
1.5.11-1
1.7.0-1
1.7.14-1
1.8.2-1
1.8.2-2
1.8.4-1
1.8.8-1
1.8.15-1
1.8.15-2~bpo10+1
1.8.15-2
1.9.8~slim-1
1.9.14+ds-1
1.9.14+ds-2
1.9.21+ds-1
2.*
2.0.1+ds-1
2.1.0+ds-1
2.1.4+ds-1
2.1.5+ds-1
2.1.7+ds-1
2.1.7+ds-2
2.2.0+ds-1
2.2.0+ds-2~bpo10+1
2.2.0+ds-2
2.2.0+ds-3
2.2.0+ds-4
2.2.0+ds-5
2.5.8+ds-1
2.5.8+ds-2
2.6.1+ds-1~bpo10+1
2.6.1+ds-1
2.9.0+ds-1
2.9.0+ds1-2
2.9.2+ds-1~bpo10+1
2.9.2+ds-1~bpo11+1
2.9.2+ds-1
3.*
3.1.1+ds-1~bpo10+1
3.1.1+ds-1~bpo11+1
3.1.1+ds-1~deb11u2
3.1.1+ds-1
3.1.8+ds-1
3.3.0+ds-1
3.3.0+ds-2
3.4.2+ds-1
3.4.3+ds-1~bpo11+1
3.4.3+ds-1
3.4.8+ds-1
3.5.2+ds-1~bpo11+1
3.5.2+ds-1
3.6.0+ds-1
3.6.1+ds-1
3.6.1+ds-2
3.6.1+ds-3
3.7.1+ds-1
3.7.3+ds-1
3.7.3+ds-2
4.*
4.0.2+ds-1
4.0.2+ds-2
4.1.0+ds-1
4.1.1+ds-1
4.2.0+ds-1
4.2.4+ds-1~bpo11+1
4.2.4+ds-1
4.3.1+ds-1~bpo11+1
4.3.1+ds-1
4.3.4+ds-1
4.3.4+ds-2
4.4.1+ds-1~bpo11+1
4.4.1+ds-1
4.5.3+ds-1~bpo11+1
4.5.3+ds-1
4.6.0+ds-1
4.6.2+ds-1
4.6.5+ds-1~bpo11+1
4.6.5+ds-1
4.6.5+ds-2
4.8.1+ds-1
4.8.1+ds-2~bpo11+1
4.8.1+ds-2~bpo12+1
4.8.1+ds-2
4.9.3+ds-1
4.9.7+ds-1
4.10.3+ds-1
4.10.3+ds-2
4.11.5+ds-1
4.11.8+ds-1
4.13.1+ds-1
4.14.3+ds-1
4.14.4+ds-1
4.14.9+ds-1
4.14.9+ds-1.1
5.*
5.7.2+ds-2~bpo13+1
5.7.2+ds-2
5.7.2+ds-3
5.7.2+ds-4
5.7.2+ds-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-7701.json"