CVE-2018-25021: Toktok Toxcore

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

The TCP Server module in toxcore before 0.2.8 doesn't free the TCP priority queue under certain conditions, which allows a remote attacker to exhaust the system's memory, causing a denial of service (DoS).

Affected products

  • Toktok Toxcore: before 0.2.8 (fixed in 0.2.8)

Published 2021-12-13. Last modified 2026-06-17.