← Back

Aria2

aria2

Vendor: Aria2 Project • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Aria2 Project
1Aria2
Aug 19, 2026
May 13, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TL...Show more
aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.Show less
4Aria2 Project
CanonicalDebian+1 more
4Aria2
Debian LinuxFedora+1 more
Jun 17, 2026
Jan 2, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.