CVE-2014-8509: Bittorrent Bootstrap-Dht

High severity, CVSS 7.5. EPSS: 5.1% chance of exploitation in the next 30 days.

The lazy_bdecode function in BitTorrent bootstrap-dht (aka Bootstrap) allows remote attackers to execute arbitrary code via a crafted packet, which triggers an out-of-bounds read, related to "Improper Indexing."

Affected products

  • Bittorrent Bootstrap-Dht: affected versions not specified

Published 2014-10-31. Last modified 2026-06-17.