VYPR

Libp2p Gossipsub

by Ipld

Source repositories

CVEs (3)

  • CVE-2026-89146HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.01

    libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process…

  • CVE-2026-33040HigMar 20, 2026
    risk 0.49cvss 7.5epss 0.01

    libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.49.3, the Gossipsub implementation accepts attacker-controlled PRUNE backoff values and may perform unchecked time arithmetic when storing backoff state. A specially…

  • CVE-2026-34219MedMar 31, 2026
    risk 0.38cvss 5.9epss 0.01

    libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a crafted PRUNE control message with an…