High severity7.5NVD Advisory· Published Sep 11, 2026
CVE-2026-89146
CVE-2026-89146
Description
libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process to panic when computing the expiry timer.
Affected products
3- Range: <=0.17.1
- Range: <=0.17.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.