{"id":"GO-2026-6138","summary":"Unbounded memory allocation in proto.UnencryptedMessage.Decode in github.com/gotd/td","details":"Unbounded memory allocation in proto.UnencryptedMessage.Decode in github.com/gotd/td","aliases":["CVE-2026-54638","GHSA-whmm-qj9r-wvr2"],"modified":"2026-08-18T17:15:27.921815293Z","published":"2026-08-18T16:38:10Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6138"},"references":[{"type":"ADVISORY","url":"https://github.com/gotd/td/security/advisories/GHSA-whmm-qj9r-wvr2"},{"type":"FIX","url":"https://github.com/gotd/td/commit/9d5d1f31ea5022d9798d84ccce15de2e91ba6baa"},{"type":"REPORT","url":"https://github.com/gotd/td/issues/1711"},{"type":"WEB","url":"https://github.com/gotd/td/releases/tag/v0.145.1"}],"affected":[{"package":{"name":"github.com/gotd/td","ecosystem":"Go","purl":"pkg:golang/github.com/gotd/td"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.145.1"}]}],"ecosystem_specific":{"imports":[{"symbols":["UnencryptedMessage.Decode"],"path":"github.com/gotd/td/proto"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6138.json"}}],"schema_version":"1.9.0"}