VYPR

floodsub

by Libp2p

CVEs (1)

  • CVE-2026-86040HigSep 17, 2026
    risk 0.49cvss 7.5epss

    libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floodsub/1.0.0 through PeerStreams.attachInboundStream in packages/floodsub/src/peer-streams.ts without protobuf element limits, then…