{"id":"CVE-2021-45848","aliases":["GHSA-p4v2-r99v-wjc2","PYSEC-2026-687"],"url":"https://o3.security/vulnerability/CVE-2021-45848","summary":"Nicotine+ DoS on Null Character in Download Request","details":"Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to crash Nicotine+ by sending a file download request with a file path containing a null character.","published":"2022-03-15T19:15:07.840Z","modified":"2026-07-08T06:03:50.635126652Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.0161,"percentile":0.73669,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"nicotine-plus","fixedVersion":"3.2.1"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HWYV53KERFH2EC4XI2IVVQFTV75E5XM6/"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202210-20"},{"type":"FIX","url":"https://github.com/nicotine-plus/nicotine-plus/issues/1777"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T06:03:50.635126652Z"}}