Description
libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies a signature with attacker-controlled msg.key but skips binding that key to msg.from when the claimed author is an RSA peer ID that does not inline a public key. An unauthenticated attacker can place a victim RSA peer ID in msg.from, sign the message with the attacker's private key, and supply the attacker's public key in msg.key, causing the message to be accepted and propagated as authored by the victim. Applications that trust message.from for validators, authorization, accounting, moderation, reputation, or audit logging can process attacker-controlled data under false origin attribution. The issue is fixed in version 16.0.5.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Spoofed message authorship leading to arbitrary processing as a victim peer
Action: Patch
AI Analysis

Impact

A flaw in libp2p Gossipsub’s StrictSign policy allowed a malicious actor to sign a message with their own key and supply an attacker‑controlled key while claiming the message originated from a victim RSA peer ID. Because the policy did not bind the provided key to the claimed author when the RSA peer ID lacked an inlined public key, the message was treated as authentic and propagated. This vulnerability arises from a lack of authentication binding (CWE‑345) and from allowing an attacker to use a different key for signature verification (CWE‑347). As a result, applications that rely on the message’s from field for authorization, accounting, reputation, or audit logging could accept attacker‑controlled data as though it had come from a trusted peer.

Affected Systems

The vulnerability affects the JavaScript implementation of libp2p, specifically the js‑libp2p package’s Gossipsub library, from version 15.0.0 up through 16.0.5. Any deployment of libp2p:js‑libp2p using the default StrictSign policy during this version range is impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity level, and the vulnerability is exploitable by an unauthenticated network attacker. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. This flaw permits credential spoofing that can compromise critical operations performed by client applications. The attack requires no privileged access and can be performed remotely by sending a crafted Gossipsub message to a target node.

Generated by OpenCVE AI on September 17, 2026 at 22:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade libp2p:js-libp2p to version 16.0.5 or later, which contains the patch for this issue.
  • After updating, ensure the Gossipsub StrictSign policy is enabled and properly configured to bind msg.key to msg.from for RSA peer IDs.
  • If an update is not immediately possible, implement a temporary validation rule that rejects messages where msg.from is an RSA peer ID without an inlined public key unless msg.key matches the actual public key of msg.from; deny propagation of such messages while awaiting the official fix.

Generated by OpenCVE AI on September 17, 2026 at 22:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c3gv-825q-fvmp libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
History

Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Libp2p
Libp2p libp2p
Vendors & Products Libp2p
Libp2p libp2p

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies a signature with attacker-controlled msg.key but skips binding that key to msg.from when the claimed author is an RSA peer ID that does not inline a public key. An unauthenticated attacker can place a victim RSA peer ID in msg.from, sign the message with the attacker's private key, and supply the attacker's public key in msg.key, causing the message to be accepted and propagated as authored by the victim. Applications that trust message.from for validators, authorization, accounting, moderation, reputation, or audit logging can process attacker-controlled data under false origin attribution. The issue is fixed in version 16.0.5.
Title libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
Weaknesses CWE-345
CWE-347
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T17:24:35.905Z

Reserved: 2026-09-04T19:29:21.057Z

Link: CVE-2026-86038

cve-icon Vulnrichment

Updated: 2026-09-17T17:24:29.895Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:18:16.927

Modified: 2026-09-30T17:51:36.337

Link: CVE-2026-86038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:15:14Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-347

    Improper Verification of Cryptographic Signature