Executive brief
Aria2 is a popular open-source download manager used to transfer files over the internet. A flaw in how it parses torrent files allows an attacker to craft a malicious torrent that causes the application to crash when processed, disrupting download operations and potentially the systems running Aria2.
Technical details
A divide-by-zero vulnerability exists in src/bittorrent_helper.cc, specifically in the processRootDictionary function. The flaw occurs when parsing a malicious torrent file where the pieceLength field is set to zero, which is then used as a divisor in a calculation without validation. An attacker can craft a malicious .torrent file and provide it to a user or service running Aria2; when the file is processed, the division-by-zero triggers an undefined behavior sanitizer error and causes a crash (Floating Point Exception). No authentication is required; the attack is triggered simply by providing a malicious torrent file to the application.
Affected products
- Aria2 Project Aria2 1.37.0 and below
Timeline
- 2026-07-28: disclosed: Issue reported on GitHub
- 2026-08-24: advisory: CVE published