Back

MEDIUM

Pidgin 2.13.0 Denial of Service via Malformed Username

Published Mar 21, 2026

Description

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, causing the application to become unavailable.

Affected products

Remediation

Red Hat statement

This Moderate impact denial of service flaw in Pidgin allows a local attacker to crash the application. By providing an excessively long username string during account creation, the application becomes unavailable when attempting to join a chat.

Red Hat mitigation

Red Hat is not aware of a practical temporary workaround that fully or partially mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

Weaknesses (2)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 21, 2026
Updated Mar 24, 2026
Reserved Mar 21, 2026
CISA Vulnrichment
Updated Mar 24, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 21, 2026