Vulnerabilities
Vulnerable Software
Aria2 Project:  Security Vulnerabilities
aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.
CVSS Score
4.8
EPSS Score
0.001
Published
2026-05-13
aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.
CVSS Score
7.8
EPSS Score
0.004
Published
2019-01-02


Contact Us

Shodan ® - All rights reserved