
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-47793 is a denial of service (DoS) vulnerability in Telegram Desktop version 2.9.2 that allows attackers to crash the application by sending an oversized message payload. The vulnerability was assigned by VulnCheck and published to NVD on January 15, 2026, despite the CVE identifier suggesting a 2021 origin. Only Telegram Desktop 2.9.2 is listed as a confirmed affected version. It carries a CVSS v3.1 base score of 7.5 (High) as scored by VulnCheck (VulnCheck Advisory, Exploit-DB).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), meaning the application fails to impose adequate constraints on buffer allocation when processing incoming message payloads. An attacker can craft a message containing approximately 9 million bytes and paste or send it through the Telegram Desktop messaging interface, triggering an application crash due to uncontrolled resource consumption. No authentication or special privileges are required to send such a message to another Telegram user. A public proof-of-concept exploit is available on Exploit-DB (Exploit-DB, VulnCheck Advisory).
Successful exploitation results in a crash of the Telegram Desktop application on the victim's system, causing a loss of availability for the messaging client. The impact is limited to availability — there is no confidentiality or integrity impact, and the vulnerability does not enable code execution or data exfiltration. Affected users running Telegram Desktop 2.9.2 would experience service disruption until the application is restarted, and repeated exploitation could constitute persistent harassment or targeted disruption (VulnCheck Advisory).
Telegram.exe process around the time of message receipt.Telegram.exe (Windows) or equivalent Telegram Desktop process without user-initiated action..dmp files) generated in the Telegram Desktop application directory or system temp folder following the crash event.Users should update Telegram Desktop to any version released after 2.9.2, as the vulnerability is specific to that version. No official patch advisory from Telegram has been published, but upgrading to the latest available release is the recommended remediation. As a temporary workaround, organizations can monitor and restrict oversized message payloads at network boundaries, or restrict Telegram Desktop usage until an update is applied (VulnCheck Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."