Rust-Libp2p
Libp2p · 6 CVEs
CVE-2026-61544
HIGH
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
Sep 15, 2026
CVE-2026-35457
HIGH
libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion
Apr 7, 2026
CVE-2026-35405
HIGH
libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers
Apr 7, 2026
CVE-2026-34219
HIGH
libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow
Mar 31, 2026
CVE-2026-33040
HIGH
libp2p-rust: Gossipsub PRUNE.backoff Duration Overflow
Mar 20, 2026
CVE-2022-23486
HIGH
libp2p-rust denial of service vulnerability from lack of resource management
Dec 7, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-61544 | libp2p-quic: Remote panic via certificate expiry race during QUIC handshake | HIGH | 0.28% | Sep 15, 2026 |
| CVE-2026-35457 | libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion | HIGH | 0.42% | Apr 7, 2026 |
| CVE-2026-35405 | libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers | HIGH | 0.49% | Apr 7, 2026 |
| CVE-2026-34219 | libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow | HIGH | 0.50% | Mar 31, 2026 |
| CVE-2026-33040 | libp2p-rust: Gossipsub PRUNE.backoff Duration Overflow | HIGH | 0.54% | Mar 20, 2026 |
| CVE-2022-23486 | libp2p-rust denial of service vulnerability from lack of resource management | HIGH | 0.71% | Dec 7, 2022 |
Showing 1 to 6 of 6 CVEs