CVE Browser

More filters (active)
CVE-2026-35480 MEDIUM

go-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headers

CVSS 6.2 EPSS 0.16% Apr 7, 2026
Go
CVE-2026-35457 HIGH

libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion

CVSS 8.2 EPSS 0.42% Apr 7, 2026
CVE-2026-35405 HIGH

libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers

CVSS 7.5 EPSS 0.49% Apr 7, 2026
CVE-2026-34219 HIGH

libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow

CVSS 8.2 EPSS 0.50% Mar 31, 2026
CVE-2026-33040 HIGH

libp2p-rust: Gossipsub PRUNE.backoff Duration Overflow

CVSS 8.7 EPSS 0.54% Mar 20, 2026
CVE-2026-32314 HIGH

Yamux remote Panic via malformed Data frame with SYN set and len = 262145

CVSS 8.7 EPSS 0.57% Mar 13, 2026
CVE-2026-31814 HIGH

Yamux remote Panic via malformed WindowUpdate credit

CVSS 8.7 EPSS 0.57% Mar 13, 2026
CVE-2023-40583 HIGH

libp2p nodes vulnerable to OOM attack

CVSS 7.5 EPSS 0.95% Aug 25, 2023
Go
CVE-2023-25568 HIGH

Boxo bitswap/server: DOS unbounded persistent memory leak

CVSS 8.2 EPSS 0.86% May 10, 2023
Go
CVE-2023-23625 HIGH

Denial of service in HAMT Decoding in go-unixfs

CVSS 7.5 EPSS 0.68% Feb 9, 2023
Go
CVE-2023-23626 HIGH

Denial of service when feeding malformed size arguments in go-bitfield

CVSS 7.5 EPSS 0.91% Feb 9, 2023
Go
CVE-2023-23631 HIGH

HAMT Decoding Panics in github.com/ipfs/go-unixfsnode

CVSS 7.5 EPSS 0.91% Feb 9, 2023
Go
CVE-2023-22460 HIGH

go-ipld-prime json codec may panic if asked to encode bytes

CVSS 7.5 EPSS 1.06% Jan 4, 2023
Go
CVE-2022-2584 HIGH

Panic when decoding invalid blocks in github.com/ipld/go-codec-dagpb

CVSS 7.5 EPSS 0.72% Dec 27, 2022
Go
CVE-2022-47547 MEDIUM

GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it continuously misbe…

CVSS 5.3 EPSS 0.53% Dec 19, 2022
CVE-2022-23495 HIGH

ProtoNode may be modified such that common method calls may panic in ipfs/go-merkledag

CVSS 7.5 EPSS 1.31% Dec 8, 2022
Go
CVE-2022-23492 HIGH

go-libp2p denial of service vulnerability from lack of resource management

CVSS 7.5 EPSS 1.01% Dec 8, 2022
Go
CVE-2022-23487 HIGH

libp2p denial of service vulnerability from lack of resource management

CVSS 7.5 EPSS 0.71% Dec 7, 2022
npm
CVE-2022-23486 HIGH

libp2p-rust denial of service vulnerability from lack of resource management

CVSS 7.5 EPSS 0.71% Dec 7, 2022
CVE-2020-26283 HIGH

Control character injection in console output

CVSS 8.8 EPSS 1.50% Mar 24, 2021
Go
CVE-2020-26279 HIGH

Path traversal

CVSS 8.1 EPSS 1.70% Mar 24, 2021
Go
CVE-2020-35909 HIGH

An issue was discovered in the multihash crate before 0.11.3 for Rust. The from_slice parsing code can panic via unsanitized data from a network server.

CVSS 7.5 EPSS 1.39% Dec 31, 2020
CVE-2020-10937 HIGH

An issue was discovered in IPFS (aka go-ipfs) 0.4.23. An attacker can generate ephemeral identities (Sybils) and leverage the IPFS connection management reputa…

CVSS 7.5 EPSS 1.16% Nov 2, 2020
Go
CVE-2020-12821 CRITICAL

Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.

CVSS 9.8 EPSS 1.94% Jul 7, 2020

Showing 1 to 24 CVEs · page 1