Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CLSA-2026-1790600625
  • TuxCare:npm/js-libp2p
  • TuxCare:npm/libp2p
TuxCare security update for 2 packages (1 CVE) 28 Sep
  • Fix available
CVE-2026-86040
  • github.com/libp2p/js-libp2p
libp2p: Unbounded RPC decode + synchronous subscription processing in @libp2p/floodsub allows unauthenticated DoS 17 Sep
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-86039
  • github.com/libp2p/js-libp2p
libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses 17 Sep
  • Fix available
  • Severity - 8.2 (High)
CVE-2026-86038
  • github.com/libp2p/js-libp2p
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID 17 Sep
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-77384
  • github.com/libp2p/js-libp2p
libp2p: Circuit relay v2 server reservation refresh leaks abort listeners and allows remote resource exhaustion 24 Aug
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-49866
  • github.com/libp2p/js-libp2p
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays 08 Jul
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-45783
  • github.com/libp2p/js-libp2p
libp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes 10 Jun
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-46679
  • github.com/libp2p/js-libp2p
libp2p: Memory DoS via subscription flood of unique topics 10 Jun
  • Fix available
  • Severity - 7.5 (High)
CVE-2023-40583
  • github.com/libp2p/go-libp2p
  • github.com/libp2p/js-libp2p
libp2p nodes vulnerable to OOM attack 25 Aug 2023
  • Fix available
  • Severity - 7.5 (High)
CVE-2022-23492
  • github.com/libp2p/go-libp2p
  • github.com/libp2p/js-libp2p
  • github.com/libp2p/rust-libp2p
go-libp2p denial of service vulnerability from lack of resource management 08 Dec 2022
  • Fix available
  • Severity - 7.5 (High)
CVE-2022-23487
  • github.com/libp2p/go-libp2p
  • github.com/libp2p/js-libp2p
  • github.com/libp2p/rust-libp2p
libp2p denial of service vulnerability from lack of resource management 07 Dec 2022
  • Fix available
  • Severity - 7.5 (High)
CVE-2022-23486
  • github.com/libp2p/js-libp2p
  • github.com/libp2p/rust-libp2p
libp2p-rust denial of service vulnerability from lack of resource management 07 Dec 2022
  • Fix available
  • Severity - 7.5 (High)