Junglewise Threat Intelligence

CVE-2026-71832: Aria2 divide by zero in bittorrent_helper

CVE-2026-71832 · Severity: medium · CVSS 6.2 · Published 2026-08-24

Technologies: Aria2 Project Aria2.

Executive brief

Aria2 is a popular open-source download manager used to transfer files over the internet. A flaw in how it parses torrent files allows an attacker to craft a malicious torrent that causes the application to crash when processed, disrupting download operations and potentially the systems running Aria2.

Technical details

A divide-by-zero vulnerability exists in src/bittorrent_helper.cc, specifically in the processRootDictionary function. The flaw occurs when parsing a malicious torrent file where the pieceLength field is set to zero, which is then used as a divisor in a calculation without validation. An attacker can craft a malicious .torrent file and provide it to a user or service running Aria2; when the file is processed, the division-by-zero triggers an undefined behavior sanitizer error and causes a crash (Floating Point Exception). No authentication is required; the attack is triggered simply by providing a malicious torrent file to the application.

Affected products

  • Aria2 Project Aria2 1.37.0 and below

Timeline

  • 2026-07-28: disclosed: Issue reported on GitHub
  • 2026-08-24: advisory: CVE published

References