---
id: CVE-2021-45848
aliases:
  - GHSA-p4v2-r99v-wjc2
  - PYSEC-2026-687
title: Nicotine+ DoS on Null Character in Download Request
summary: Nicotine+ DoS on Null Character in Download Request
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: nicotine-plus
product: nicotine-plus
ecosystem: pip
affected:
  - 'nicotine-plus >= 3.0.3, < 3.2.1'
patched:
  - nicotine-plus 3.2.1
published: '2022-03-16'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-p4v2-r99v-wjc2'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-45848'
  - url: 'https://github.com/nicotine-plus/nicotine-plus/issues/1777'
  - url: >-
      https://github.com/nicotine-plus/nicotine-plus/commit/0e3e2fac27a518f0a84330f1ddf1193424522045
  - url: 'https://github.com/nicotine-plus/nicotine-plus'
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HWYV53KERFH2EC4XI2IVVQFTV75E5XM6
  - url: 'https://security.gentoo.org/glsa/202210-20'
tags:
  - osv
  - pip
epss: 0.01624
epssPercentile: 0.75075
ingestedAt: '2026-07-08T18:25:51.516Z'
---

## Overview

Denial of service (DoS) vulnerability in Nicotine+ starting with version 3.0.3 and prior to version 3.2.1 allows a user with a modified Soulseek client to crash Nicotine+ by sending a file download request with a file path containing a null character.

## Affected packages

- `nicotine-plus >= 3.0.3, < 3.2.1`

## Remediation

Upgrade to a patched release:

- `nicotine-plus 3.2.1`
