CVE-2026-57081

HIGH

Net::BitTorrent <= 2.0.1 - Bencode Memory Exhaustion

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-57081. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-57081, a memory exhaustion vulnerability in Net::BitTorrent (Perl) versions through 2.0.1. The module includes placeholder code with no functional exploit implementation, only a basic connectivity check and warnings about missing PoC code.

Description

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested list or dictionary level with no depth cap, and each recursive call receives the remaining buffer by value while the list and dictionary branches capture the whole remainder, so every live recursion frame keeps its own copy of the shrinking buffer (O(N^2) bytes for an N-deep input). The decoder runs on every untrusted bencode source: .torrent files, BEP09 metadata fetched from peers, DHT messages, and tracker responses. A bencoded input of roughly 150,000 nested lists (about 150 KB on the wire) drives multi-gigabyte peak memory, so one short message from any peer, or one crafted .torrent file or magnet link, terminates the client.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-57081_netbittorrent_versions_through.py

This repository contains an auto-generated stub module for CVE-2026-57081, a memory exhaustion vulnerability in Net::BitTorrent (Perl) versions through 2.0.1. The module includes placeholder code with no functional exploit implementation, only a basic connectivity check and warnings about missing PoC code.

Classification
Stub 98%
Attack Type
Dos
Complexity
Moderate
Reliability
Theoretical
Target: Net::BitTorrent (Perl) versions through 2.0.1
No auth needed
Prerequisites: Network access to a vulnerable Net::BitTorrent service · Ability to send deeply nested bencoded input
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0028
EPSS Percentile 20.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400 CWE-674
Status published
Products (2)
SANKO/Net::BitTorrent < 2.0.1
SANKO/Net::BitTorrent < 2.1.0
Published Jun 30, 2026
Tracked Since Jun 30, 2026