CVE-2020-26164: Kde Kdeconnect

Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.

In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack.

Affected products

  • Kde Kdeconnect: before 20.08.2 (fixed in 20.08.2)
  • Opensuse Backports Sle: version 15.0 only
  • Opensuse Leap: version 15.1 only; version 15.2 only

Published 2020-10-07. Last modified 2026-06-17.