Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-c3gv-825q-fvmp
  • npm/@libp2p/gossipsub
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID 17 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-cwc9-cp4j-mcvv
  • npm/@libp2p/gossipsub
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays 10 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-4f8r-922h-2vgv
  • npm/@libp2p/gossipsub
js-libp2p: Memory DoS via subscription flood of unique topics 21 May
  • Fix available
  • Severity - 7.5 (High)