CVE-2016-10188: Bitlbee

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

Use-after-free vulnerability in bitlbee-libpurple before 3.5 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code by causing a file transfer connection to expire.

Affected products

  • Bitlbee Bitlbee: up to and including 3.4.2

Published 2017-03-14. Last modified 2026-06-17.