← Back

Aria2 Project

aria2_project

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Aria2
aria2

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Aria2 Project
1Aria2
Aug 19, 2026
May 13, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TL...Show more
aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.Show less
4Aria2 Project
CanonicalDebian+1 more
4Aria2
Debian LinuxFedora+1 more
Jun 17, 2026
Jan 2, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.