Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

libp2p — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting libp2p. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Libp2p serves as a modular networking stack for peer-to-peer applications, enabling decentralized communication protocols. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and insecure default configurations. While no major public security incidents have been widely documented, the 13 recorded CVEs highlight potential risks in its implementation. Security characteristics include its decentralized nature but also complexity in secure deployment. Developers must carefully implement access controls and validate all inputs to mitigate risks, as the library's extensive functionality surface area increases potential attack vectors when not properly configured.

CVE ID Title CVSS Severity Published
CVE-2026-77384 libp2p: Circuit relay v2 server reservation refresh leaks abort listeners and allows remote resource exhaustion — js-libp2p CWE-400 7.5 High 2026-08-24
CVE-2026-73568 py-libp2p: yamux connection DoS via oversized data frame — py-libp2p CWE-400 7.5 High 2026-08-13
CVE-2026-49866 libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays — js-libp2p CWE-770 7.5 High 2026-07-08
CVE-2026-45783 libp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes — js-libp2p CWE-20 7.5 High 2026-06-10
CVE-2026-46679 libp2p: Memory DoS via subscription flood of unique topics — js-libp2p CWE-20 7.5 High 2026-06-10
CVE-2026-35457 libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion — rust-libp2p CWE-770 8.2 High 2026-04-07
CVE-2026-35405 libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers — rust-libp2p CWE-770 7.5 High 2026-04-07
CVE-2026-34219 libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow — rust-libp2p CWE-190 7.5AI High AI 2026-03-31
CVE-2026-33040 libp2p-rust: Gossipsub PRUNE.backoff Duration Overflow — rust-libp2p CWE-190 7.5 - 2026-03-20
CVE-2026-32314 Yamux remote Panic via malformed Data frame with SYN set and len = 262145 — rust-yamux CWE-248 7.5AI High AI 2026-03-13
CVE-2026-31814 Yamux remote Panic via malformed WindowUpdate credit — rust-yamux CWE-190 7.5 - 2026-03-13
CVE-2025-29606 py-libp2p 安全漏洞 — py-libp2p CWE-770 4.3 Medium 2025-07-14
CVE-2024-32984 Yamux Memory Exhaustion Vulnerability via Active::pending_frames property — rust-yamux CWE-400 7.5 High 2024-05-01
CVE-2023-40583 libp2p nodes vulnerable to OOM attack — go-libp2p CWE-400 7.5 High 2023-08-25
CVE-2023-39533 libp2p nodes vulnerable to attack using large RSA keys — go-libp2p CWE-770 7.5 High 2023-08-08
CVE-2022-23492 go-libp2p denial of service vulnerability from lack of resource management — go-libp2p CWE-400 7.5 High 2022-12-08
CVE-2022-23487 libp2p denial of service vulnerability from lack of resource management — js-libp2p CWE-400 7.5 High 2022-12-07
CVE-2022-23486 libp2p-rust denial of service vulnerability from lack of resource management — rust-libp2p CWE-400 7.5 High 2022-12-07

This page lists every published CVE security advisory associated with libp2p. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.