VYPR

npm package

@libp2p/kad-dht

pkg:npm/%40libp2p/kad-dht

Vulnerabilities (1)

  • CVE-2026-45783HigJun 10, 2026
    affected < 16.2.6fixed 16.2.6

    libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote peer can exhaust the disk storage of any @libp2p/kad-dht node running in server mode by sending an unbounded stream of PUT_VALUE messages whose keys bypass all con