Description
libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a remote peer presented a valid short-lived libp2p TLS certificate and delayed the final TLS 1.3 handshake fragment until after the certificate expired. In the Quinn post-handshake upgrade path, transports/quic/src/connection/connecting.rs called libp2p_tls::certificate::parse a second time in remote_peer_id and used expect on the result. The repeated wall-clock validity check could reject the now-expired certificate, causing the expect call to terminate any application exposing an affected libp2p-quic listener. This vulnerability is fixed in 0.13.1.
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Application Crash
Action: Patch
AI Analysis

Impact

libp2p‑rust exposes a crash in its QUIC transport when a remote peer presents a valid short‑lived TLS certificate that expires during the QUIC handshake. The implementation re‑parses the certificate after the handshake and, using an unsafe `expect` call, aborts the process if the certificate has become invalid. An attacker can coordinate the timing of a connection to trigger this race condition, causing the entire listening application to terminate.

Affected Systems

The vulnerable component is the libp2p‑quic module in the Rust implementation of libp2p, distributed as libp2p:rust-libp2p. All releases before version 0.13.1 are affected. Any Rust application that links against libp2p:rust-libp2p 0.13.0 or earlier and exposes a QUIC listener is potentially susceptible.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. The EPSS score is below 1 %, suggesting a low probability of abuse in the near term. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote, requiring an attacker to initiate a QUIC connection to a vulnerable node and time a certificate expiration during the handshake. Although no public exploits are known, the crash and high severity warrant immediate patching.

Generated by OpenCVE AI on September 20, 2026 at 11:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libp2p:rust-libp2p to version 0.13.1 or later
  • Rebuild and redeploy the application so that the upgraded library is used
  • If an upgrade cannot be performed immediately, restrict inbound QUIC traffic to trusted peers or monitor for sudden application crashes to mitigate the impact

Generated by OpenCVE AI on September 20, 2026 at 11:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5hq8-qhww-jm7q libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
History

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Libp2p
Libp2p rust-libp2p
Vendors & Products Libp2p
Libp2p rust-libp2p

Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a remote peer presented a valid short-lived libp2p TLS certificate and delayed the final TLS 1.3 handshake fragment until after the certificate expired. In the Quinn post-handshake upgrade path, transports/quic/src/connection/connecting.rs called libp2p_tls::certificate::parse a second time in remote_peer_id and used expect on the result. The repeated wall-clock validity check could reject the now-expired certificate, causing the expect call to terminate any application exposing an affected libp2p-quic listener. This vulnerability is fixed in 0.13.1.
Title libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
Weaknesses CWE-248
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Libp2p Rust-libp2p
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T16:48:19.068Z

Reserved: 2026-07-10T16:27:03.093Z

Link: CVE-2026-61544

cve-icon Vulnrichment

Updated: 2026-09-17T16:48:12.820Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:17:35.147

Modified: 2026-09-30T17:51:36.337

Link: CVE-2026-61544

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T12:00:13Z

Weaknesses