CVE-2026-8367: ARIA2 Project ARIA2
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.
Affected products
- ARIA2 Project ARIA2: before 1.37.0 (fixed in 1.37.0)
Published 2026-05-13. Last modified 2026-08-19.