CVE-2016-7164: Libtorrent

High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.

The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segmentation fault and crash) via a crafted GZIP response.

Affected products

Published 2017-02-07. Last modified 2026-06-17.