Versions of bittorrent-dht prior to 5.1.3 are affected by a remote memory disclosure vulnerability. This vulnerability allows an attacker to send a specific series of of messages to a listening peer and get it to reveal internal memory.
There are two mitigating factors here, that slightly reduce the impact of this vulnerability:
Update to version 5.1.3 or later.
{
"nvd_published_at": null,
"severity": "MODERATE",
"github_reviewed_at": "2020-08-31T18:09:58Z",
"cwe_ids": [
"CWE-201"
],
"github_reviewed": true
}