🔐 CVE Alert

CVE-2019-25544

MEDIUM 6.2

Pidgin 2.13.0 Denial of Service via Malformed Username

CVSS Score
6.2
EPSS Score
0.0%
EPSS Percentile
3th

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, causing the application to become unavailable.

CWE CWE-807
Vendor pidgin
Product pidgin
Published Mar 21, 2026
Last Updated Mar 24, 2026
Stay Ahead of the Next One

Get instant alerts for pidgin pidgin

Be the first to know when new medium vulnerabilities affecting pidgin pidgin are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

Pidgin / Pidgin
2.13.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
exploit-db.com: https://www.exploit-db.com/exploits/46930 pidgin.im: https://pidgin.im/ vulncheck.com: https://www.vulncheck.com/advisories/pidgin-denial-of-service-via-malformed-username

Credits

Alejandra Sánchez