VYPR

crates.io package

libp2p-gossipsub

pkg:cargo/libp2p-gossipsub

Vulnerabilities (2)

  • CVE-2026-34219MedMar 31, 2026
    affected < 0.49.4fixed 0.49.4

    libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a crafted PRUNE control message with an at

  • CVE-2026-33040HigMar 20, 2026
    affected < 0.49.3fixed 0.49.3

    libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.49.3, the Gossipsub implementation accepts attacker-controlled PRUNE backoff values and may perform unchecked time arithmetic when storing backoff state. A specially cr