CVE Browser
go-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headers
libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion
libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers
libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow
libp2p-rust: Gossipsub PRUNE.backoff Duration Overflow
Yamux remote Panic via malformed Data frame with SYN set and len = 262145
Yamux remote Panic via malformed WindowUpdate credit
libp2p nodes vulnerable to OOM attack
Boxo bitswap/server: DOS unbounded persistent memory leak
Denial of service in HAMT Decoding in go-unixfs
Denial of service when feeding malformed size arguments in go-bitfield
HAMT Decoding Panics in github.com/ipfs/go-unixfsnode
go-ipld-prime json codec may panic if asked to encode bytes
Panic when decoding invalid blocks in github.com/ipld/go-codec-dagpb
GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it continuously misbe…
ProtoNode may be modified such that common method calls may panic in ipfs/go-merkledag
go-libp2p denial of service vulnerability from lack of resource management
libp2p denial of service vulnerability from lack of resource management
libp2p-rust denial of service vulnerability from lack of resource management
Control character injection in console output
Path traversal
An issue was discovered in the multihash crate before 0.11.3 for Rust. The from_slice parsing code can panic via unsanitized data from a network server.
An issue was discovered in IPFS (aka go-ipfs) 0.4.23. An attacker can generate ephemeral identities (Sybils) and leverage the IPFS connection management reputa…
Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.
Showing 1 to 24 CVEs · page 1