Description
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v5hw-cv9c-rpg7 | libp2p-rendezvous: Unbounded rendezvous DISCOVER cookies enable remote memory exhaustion |
References
History
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1. | |
| Title | libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T17:53:37.355Z
Reserved: 2026-04-02T19:25:52.193Z
Link: CVE-2026-35457
Updated: 2026-04-07T17:53:25.830Z
Status : Received
Published: 2026-04-07T15:17:43.587
Modified: 2026-04-07T15:17:43.587
Link: CVE-2026-35457
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA