Security Advisories (2)
CVE-2026-57080 (2026-06-30)

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framing in _process_messages trusts the 4-byte length prefix sent by a connected peer with no upper bound, while receive_data appends every inbound byte to the input buffer. A peer announces a length prefix of up to about 4 GiB and then streams bytes; the decoder waits until the buffer holds the full message before processing it, so the buffer grows without limit. Peer connections are unauthenticated, so any peer in the swarm exhausts the downloading process's memory. The largest legitimate message is a 16 KiB piece block, so any announced length far above that is anomalous.

CVE-2026-57081 (2026-06-30)

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining buffer by value while the list and dictionary branches capture the whole remainder, so every live recursion frame keeps its own copy of the shrinking buffer (O(N^2) bytes for an N-deep input). The decoder runs on every untrusted bencode source: .torrent files, BEP09 metadata fetched from peers, DHT messages, and tracker responses. A bencoded input of roughly 150,000 nested lists (about 150 KB on the wire) drives multi-gigabyte peak memory, so one short message from any peer, or one crafted .torrent file or magnet link, terminates the client.

NAME

Net::BitTorrent::Protocol::BEP55 - Holepunching Extension (NAT Traversal)

SYNOPSIS

# Inherits from Net::BitTorrent::Protocol::BEP11
use Net::BitTorrent::Protocol::BEP55;

my $p = Net::BitTorrent::Protocol::BEP55->new(...);

# Ask a mutual peer to introduce us to a target
$p->send_hp_rendezvous($target_peer_id);

# Handle incoming connection requests
$p->on(hp_connect => sub ( $emitter, $ip, $port ) {
    say "Attempting holepunch connect to $ip:$port";
});

DESCRIPTION

Net::BitTorrent::Protocol::BEP55 implements the Holepunching Extension (BEP 55). This extension allows two peers who are both behind NAT (Network Address Translation) to coordinate a simultaneous UDP connection (uTP) using a third, mutually connected peer as a signaling relay.

It runs as a sub-protocol of the Extension Protocol (BEP 10) under the name ut_holepunch.

METHODS

send_hp_rendezvous( $target_id )

Requests a rendezvous with a target peer.

$p->send_hp_rendezvous( $target_peer_id );

This method asks the peer to act as a mediator to coordinate a holepunch with another peer.

Expected parameters:

$target_id

The 20-byte binary peer ID of the target.

send_hp_connect( $ip, $port )

Instructs a peer to connect to a specific address.

$p->send_hp_connect( '1.2.3.4', 6881 );

This method is sent by the mediator to the target peer, instructing it to initiate a uTP connection.

Expected parameters:

$ip

The IP address.

$port

The port number.

send_hp_error( $err_code )

Sends a holepunch error.

$p->send_hp_error( 0x01 );

This method informs the requester that the holepunch operation failed.

Expected parameters:

$err_code

The error code (e.g., 0x01 for peer not found).

hp_rendezvous event

Emitted when a rendezvous request is received.

$p->on( hp_rendezvous => sub ( $self, $id ) { ... } );

Expected parameters:

$id

The target peer ID.

hp_connect event

Emitted when a connect instruction is received.

$p->on( hp_connect => sub ( $self, $ip, $port ) { ... } );

Expected parameters:

$ip

The IP to connect to.

$port

The port to connect to.

hp_error event

Emitted when a holepunch error is received.

$p->on( hp_error => sub ( $self, $err ) { ... } );

Expected parameters:

$err

The error code.

Specifications

  • BEP 55: Holepunching

AUTHOR

Sanko Robinson - https://github.com/sanko

COPYRIGHT

Copyright (C) 2008-2026 by Sanko Robinson.

This library is free software; you can redistribute it and/or modify it under the terms of the Artistic License 2.0.