CVE-2026-8367: ARIA2 Project ARIA2

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.

Affected products

Published 2026-05-13. Last modified 2026-08-19.