VYPR

crates.io package

libp2p-rendezvous

pkg:cargo/libp2p-rendezvous

Vulnerabilities (2)

  • CVE-2026-35457HigApr 7, 2026
    affected < 0.17.1fixed 0.17.1

    libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnera

  • CVE-2026-35405HigApr 7, 2026
    affected < 0.17.1fixed 0.17.1

    libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on how many namespaces a single peer can register. A malicious peer can just keep registering unique namespaces in a loop and the serve