Description
libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floodsub/1.0.0 through PeerStreams.attachInboundStream in packages/floodsub/src/peer-streams.ts without protobuf element limits, then processRpc and processRpcSubOpt in packages/floodsub/src/floodsub.ts synchronously process the subscriptions array without a per-frame cap. A single bounded-size frame can decode into millions of empty subscription entries that block the event loop, while hundreds of thousands of unique-topic SUBSCRIBE entries allocate PeerSet objects in this.topics that are not removed after peer removal or stop. Empty entries cause CPU exhaustion but do not grow this.topics; persistent memory growth requires unique topics. The subscription path bypasses message signature validation and the message-only processing queue, allowing a remote peer to cause sustained CPU denial of service, memory exhaustion, out-of-memory termination, and node unavailability. The issue is fixed in version 11.0.26.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability lies in the floodsub protocol of the libp2p JavaScript implementation, where unauthenticated RPC frames received on the /floodsub/1.0.0 stream are decoded without size limits and processed synchronously. A single modest‑sized frame can expand to millions of empty subscription entries, blocking the event loop, while large numbers of distinct topic subscriptions allocate PeerSet objects that persist in the node’s topic registry. This bypasses message signature validation and the normal queue, enabling a remote peer to perform sustained CPU denial of service, memory exhaustion, out‑of‑memory termination, and make the node unavailable.

Affected Systems

The affected software is the @libp2p/floodsub module used within the libp2p JavaScript stack (js-libp2p). Versions prior to 11.0.26 are vulnerable; the fix is included in floodsub‑v11.0.26. Any node running an earlier release and exposing the floodsub protocol to the network is at risk.

Risk and Exploitability

With a CVSS score of 7.5, the vulnerability presents moderate‑high severity. EPSS is not available, and the issue is not listed in CISA’s KEV catalog, but the attack path requires only an unauthenticated connection on a known protocol endpoint, making exploitation straightforward for any peer on a libp2p network. The lack of frame size limits and synchronous processing ensures that an attacker can easily trigger the denial‑of‑service behavior, giving this vulnerability a high likelihood of impact in real‑world deployments.

Generated by OpenCVE AI on September 17, 2026 at 21:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the libp2p JavaScript stack to floodsub v11.0.26 or later.
  • Limit inbound RPC connections to trusted peers, or restrict the floodsub protocol to a whitelist of known peers.
  • Disable floodsub if not required, or apply user‑defined limits on subscription arrays to prevent large request payloads.
  • Monitor node resource usage and set alerts for abnormal CPU or memory consumption to detect exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 21:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Libp2p
Libp2p libp2p
Vendors & Products Libp2p
Libp2p libp2p

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floodsub/1.0.0 through PeerStreams.attachInboundStream in packages/floodsub/src/peer-streams.ts without protobuf element limits, then processRpc and processRpcSubOpt in packages/floodsub/src/floodsub.ts synchronously process the subscriptions array without a per-frame cap. A single bounded-size frame can decode into millions of empty subscription entries that block the event loop, while hundreds of thousands of unique-topic SUBSCRIBE entries allocate PeerSet objects in this.topics that are not removed after peer removal or stop. Empty entries cause CPU exhaustion but do not grow this.topics; persistent memory growth requires unique topics. The subscription path bypasses message signature validation and the message-only processing queue, allowing a remote peer to cause sustained CPU denial of service, memory exhaustion, out-of-memory termination, and node unavailability. The issue is fixed in version 11.0.26.
Title libp2p: Unbounded RPC decode + synchronous subscription processing in @libp2p/floodsub allows unauthenticated DoS
Weaknesses CWE-400
CWE-401
CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:19:11.341Z

Reserved: 2026-09-04T19:29:21.058Z

Link: CVE-2026-86040

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:18:17.250

Modified: 2026-09-24T21:19:05.340

Link: CVE-2026-86040

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-770

    Allocation of Resources Without Limits or Throttling