Impact
The vulnerability lies in the floodsub protocol of the libp2p JavaScript implementation, where unauthenticated RPC frames received on the /floodsub/1.0.0 stream are decoded without size limits and processed synchronously. A single modest‑sized frame can expand to millions of empty subscription entries, blocking the event loop, while large numbers of distinct topic subscriptions allocate PeerSet objects that persist in the node’s topic registry. This bypasses message signature validation and the normal queue, enabling a remote peer to perform sustained CPU denial of service, memory exhaustion, out‑of‑memory termination, and make the node unavailable.
Affected Systems
The affected software is the @libp2p/floodsub module used within the libp2p JavaScript stack (js-libp2p). Versions prior to 11.0.26 are vulnerable; the fix is included in floodsub‑v11.0.26. Any node running an earlier release and exposing the floodsub protocol to the network is at risk.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability presents moderate‑high severity. EPSS is not available, and the issue is not listed in CISA’s KEV catalog, but the attack path requires only an unauthenticated connection on a known protocol endpoint, making exploitation straightforward for any peer on a libp2p network. The lack of frame size limits and synchronous processing ensures that an attacker can easily trigger the denial‑of‑service behavior, giving this vulnerability a high likelihood of impact in real‑world deployments.
OpenCVE Enrichment