check transport progress-token length before allocating the payload buffer
partially fixed publicly
details
Finding IDs
F-TELEGRAM-OOM-001
Status
partially fixed publicly
Disclosure date
Note
transportDecodeProgressToken checks data.length before subtracting 24. This matches the primary underflow vector; it does not establish fixes for every accompanying MTInputStream short-read case. The full report and release rollout were not independently retested.
F-TELEGRAM-OOM-001: Resource limits. Token-length underflow leads to an oversized allocation. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.