CVE Vulnerabilities

CVE-2020-12474

Published: May 01, 2020 | Modified: Jun 17, 2026
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public URL or a group chat invitation URL.

Affected Software

NameVendorStart VersionEnd Version
TelegramTelegram*6.0.1 (including)
Telegram_desktopTelegram*2.0.1 (including)
Telegram-desktopUbuntubionic*
Telegram-desktopUbuntueoan*
Telegram-desktopUbuntufocal*

References