VYPR
High severity8.1NVD Advisory· Published Mar 17, 2022· Updated Jun 17, 2026

CVE-2022-24759

CVE-2022-24759

Description

@chainsafe/libp2p-noise contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. @chainsafe/libp2p-noise before 4.1.2 and 5.0.3 does not correctly validate signatures during the handshake process. This may allow a man-in-the-middle to pose as other peers and get those peers banned. Users should upgrade to version 4.1.2 or 5.0.3 to receive a patch. There are currently no known workarounds.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@chainsafe/libp2p-noisenpm
< 4.1.24.1.2
@chainsafe/libp2p-noisenpm
>= 5.0.0, < 5.0.35.0.3

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.