Debian Package Tracker
Register | Log in
Subscribe

telegram-desktop

fast and secure messaging application

Choose email to subscribe with

general
  • source: telegram-desktop (main)
  • version: 5.7.2+ds-5
  • maintainer: Nicholas Guriev (DMD) (DM)
  • arch: amd64 arm64 armel armhf hurd-i386 i386 ia64 mips64el ppc64el sh4 x32
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.1.1+ds-1~deb11u2
  • oldstable: 4.6.5+ds-2
  • stable-bpo: 5.7.2+ds-2~bpo13+1
  • testing: 5.7.2+ds-5
  • unstable: 5.7.2+ds-5
versioned links
  • 3.1.1+ds-1~deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.6.5+ds-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.7.2+ds-2~bpo13+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.7.2+ds-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • telegram-desktop (45 bugs: 0, 36, 9, 0)
action needed
A new upstream version is available: 7.2.9 high
A new upstream version 7.2.9 is available, you should consider packaging it.
Created: 2026-01-02 Last update: 2026-10-10 16:00
3 security issues in sid high

There are 3 open security issues in sid.

3 important issues:
  • CVE-2026-7701: A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. There is ongoing doubt regarding the real existence of this vulnerability. Upgrading to version 6.7.6 is able to resolve this issue. Upgrading the affected component is recommended. The vendor provides this rationale for the dispute: "[T]he described scenario does not lead to any security issue or vulnerability, and only causes a one-time crash. In the outlined scenario, the targeted user must perform an active action, which doesn't produce any consequences after the app is relaunched."
  • CVE-2026-94488: Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group by a member (it is not necessary for the message author to be a member of a group).
  • CVE-2026-107181: Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.
Created: 2026-07-18 Last update: 2026-10-08 22:00
3 security issues in forky high

There are 3 open security issues in forky.

3 important issues:
  • CVE-2026-7701: A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. There is ongoing doubt regarding the real existence of this vulnerability. Upgrading to version 6.7.6 is able to resolve this issue. Upgrading the affected component is recommended. The vendor provides this rationale for the dispute: "[T]he described scenario does not lead to any security issue or vulnerability, and only causes a one-time crash. In the outlined scenario, the targeted user must perform an active action, which doesn't produce any consequences after the app is relaunched."
  • CVE-2026-94488: Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group by a member (it is not necessary for the message author to be a member of a group).
  • CVE-2026-107181: Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.
Created: 2026-07-18 Last update: 2026-10-08 22:00
3 security issues in bookworm high

There are 3 open security issues in bookworm.

3 important issues:
  • CVE-2026-7701: A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. There is ongoing doubt regarding the real existence of this vulnerability. Upgrading to version 6.7.6 is able to resolve this issue. Upgrading the affected component is recommended. The vendor provides this rationale for the dispute: "[T]he described scenario does not lead to any security issue or vulnerability, and only causes a one-time crash. In the outlined scenario, the targeted user must perform an active action, which doesn't produce any consequences after the app is relaunched."
  • CVE-2026-94488: Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group by a member (it is not necessary for the message author to be a member of a group).
  • CVE-2026-107181: Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.
Created: 2026-07-18 Last update: 2026-10-08 22:00
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-7701: A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. There is ongoing doubt regarding the real existence of this vulnerability. Upgrading to version 6.7.6 is able to resolve this issue. Upgrading the affected component is recommended. The vendor provides this rationale for the dispute: "[T]he described scenario does not lead to any security issue or vulnerability, and only causes a one-time crash. In the outlined scenario, the targeted user must perform an active action, which doesn't produce any consequences after the app is relaunched."
Created: 2026-07-18 Last update: 2026-08-02 20:32
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2026-09-02 Last update: 2026-10-10 19:30
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2025-12-14 Last update: 2026-10-10 17:30
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2026-04-22 Last update: 2026-04-22 00:01
debian/patches: 12 patches to forward upstream low

Among the 24 debian patches available in version 5.7.2+ds-5 of the package, we noticed the following issues:

  • 12 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-04-21 21:31
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.6.2).
Created: 2024-04-07 Last update: 2026-04-21 16:49
testing migrations
  • This package will soon be part of the abseil-20260817 transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • This package will soon be part of the auto-abseil transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-04-26] telegram-desktop 5.7.2+ds-5 MIGRATED to testing (Debian testing watch)
  • [2026-04-21] Accepted telegram-desktop 5.7.2+ds-5 (source) into unstable (Nicholas Guriev)
  • [2026-02-06] Accepted telegram-desktop 5.7.2+ds-2~bpo13+1 (source amd64) into stable-backports (Debian FTP Masters) (signed by: bage@debian.org)
  • [2025-12-23] telegram-desktop 5.7.2+ds-4 MIGRATED to testing (Debian testing watch)
  • [2025-12-17] Accepted telegram-desktop 5.7.2+ds-4 (source) into unstable (Nicholas Guriev)
  • [2025-12-14] Accepted telegram-desktop 5.7.2+ds-3 (source) into unstable (Nicholas Guriev)
  • [2025-12-14] telegram-desktop 5.7.2+ds-2 MIGRATED to testing (Debian testing watch)
  • [2025-12-03] Accepted telegram-desktop 5.7.2+ds-2 (source) into unstable (Nicholas Guriev)
  • [2025-01-23] telegram-desktop REMOVED from testing (Debian testing watch)
  • [2024-10-22] telegram-desktop 4.14.9+ds-1.1 MIGRATED to testing (Debian testing watch)
  • [2024-10-19] telegram-desktop REMOVED from testing (Debian testing watch)
  • [2024-09-03] telegram-desktop 4.14.9+ds-1.1 MIGRATED to testing (Debian testing watch)
  • [2024-08-25] Accepted telegram-desktop 4.14.9+ds-1.1 (source) into unstable (Andrey Rakhmatullin) (signed by: Andrey Rahmatullin)
  • [2024-08-25] telegram-desktop REMOVED from testing (Debian testing watch)
  • [2024-05-31] telegram-desktop 4.14.9+ds-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-21] telegram-desktop REMOVED from testing (Debian testing watch)
  • [2024-02-15] telegram-desktop 4.14.9+ds-1 MIGRATED to testing (Debian testing watch)
  • [2024-02-12] telegram-desktop REMOVED from testing (Debian testing watch)
  • [2024-01-27] telegram-desktop 4.14.9+ds-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-21] Accepted telegram-desktop 4.14.9+ds-1 (source) into unstable (Nicholas Guriev)
  • [2024-01-19] telegram-desktop 4.14.4+ds-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-14] Accepted telegram-desktop 4.14.4+ds-1 (source) into unstable (Nicholas Guriev)
  • [2024-01-13] telegram-desktop 4.14.3+ds-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-08] Accepted telegram-desktop 4.14.3+ds-1 (source) into unstable (Nicholas Guriev)
  • [2024-01-03] telegram-desktop 4.13.1+ds-1 MIGRATED to testing (Debian testing watch)
  • [2023-12-28] Accepted telegram-desktop 4.13.1+ds-1 (source) into unstable (Nicholas Guriev)
  • [2023-11-25] telegram-desktop 4.11.8+ds-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-20] Accepted telegram-desktop 4.11.8+ds-1 (source) into unstable (Nicholas Guriev)
  • [2023-11-08] Accepted telegram-desktop 4.11.5+ds-1 (source) into unstable (Nicholas Guriev)
  • [2023-11-05] telegram-desktop 4.10.3+ds-2 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 45 47
  • RC: 2
  • I&N: 34 36
  • M&W: 9
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • debian patches

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing