Description
libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerRecord.peerId in the signed payload to equal the signer peer ID derived by RecordEnvelope.openAndCertify. The expectedPeer option checks only the envelope signer, and the gossipsub Peer Exchange path can provide the attacker's own peer ID as expectedPeer. An attacker can therefore sign a record with the attacker's key, place a victim peer ID and attacker-controlled multiaddrs in the payload, and have certified addresses stored for the victim. The poisoned addresses can cause address-book corruption, dial redirection or failure, routing manipulation, and reachability disruption, although the connection upgrade still verifies remote peer identity and prevents a complete identity takeover. The issue is fixed in version 12.0.24.
Published: 2026-09-17
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized PeerRecord injection leading to address corruption and potential routing failures
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker to create a malicious PeerRecord that contains a victim’s peer ID but is signed with the attacker’s cryptographic key. Because the PeerStore verification logic only checks that the signature comes from the expected peer and does not confirm that the signed payload’s peerId matches the signer, the malicious record can be accepted and stored as if it were legitimate. The stored addresses can then be used for address‑book corruption, directed or redirected connections, and reachability disruption. While the base layer still verifies remote peer identity during connection upgrades, the poisoned addresses enable attackers to influence path selection and potentially deny service to the victim.

Affected Systems

This risk applies to environments that use libp2p/peer-store versions between 8.0.0 and 12.0.24 inclusive, specifically the @libp2p/peer-store component of the libp2p JavaScript networking stack.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity flaw. No EPSS score is reported, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves the gossipsub Peer Exchange path, where an attacker can impersonate a peer ID during peer discovery. Exploitation requires the attacker to be able to inject a custom PeerRecord into the network, which may be feasible for anyone with network access to the peer discovery mechanisms.

Generated by OpenCVE AI on September 17, 2026 at 21:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the libp2p/peer-store patch by upgrading to version 12.0.24 or newer.
  • Disable or limit the gossipsub Peer Exchange path, or configure expectedPeer to a trusted list to block acceptance of attacker‑signed PeerRecords.
  • Audit the contents of the peer store for unexpected or suspicious addresses and remove or quarantine any entries that do not correspond to known, trusted peers.

Generated by OpenCVE AI on September 17, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vrf4-mx87-p53w libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses
History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Libp2p
Libp2p libp2p
Vendors & Products Libp2p
Libp2p libp2p

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerRecord.peerId in the signed payload to equal the signer peer ID derived by RecordEnvelope.openAndCertify. The expectedPeer option checks only the envelope signer, and the gossipsub Peer Exchange path can provide the attacker's own peer ID as expectedPeer. An attacker can therefore sign a record with the attacker's key, place a victim peer ID and attacker-controlled multiaddrs in the payload, and have certified addresses stored for the victim. The poisoned addresses can cause address-book corruption, dial redirection or failure, routing manipulation, and reachability disruption, although the connection upgrade still verifies remote peer identity and prevents a complete identity takeover. The issue is fixed in version 12.0.24.
Title libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses
Weaknesses CWE-290
CWE-345
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:48:54.323Z

Reserved: 2026-09-04T19:29:21.058Z

Link: CVE-2026-86039

cve-icon Vulnrichment

Updated: 2026-09-21T20:48:48.685Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:18:17.090

Modified: 2026-09-24T21:19:05.340

Link: CVE-2026-86039

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-345

    Insufficient Verification of Data Authenticity