Description
libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process to panic when computing the expiry timer.
Published: 2026-09-11
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Update package
AI Analysis

Impact

libp2p-rendezvous 0.17.1 does not validate the time‑to‑live value that a rendezvous server sends in a discovery response. An attacker who can control a rendezvous server can set the TTL to an unbounded or excessively large value, causing the client to perform arithmetic that overflows the timer computation. The overflow results in a panic that crashes the client process, effectively denying service to the affected node.

Affected Systems

The vulnerability exists in the libp2p-rendezvous library distributed by the libp2p project. Version 0.17.1 and earlier are affected. No lower bound was listed, so any deployment that uses 0.17.1 or an earlier released version is at risk.

Risk and Exploitability

The CVSS score of 8.7 indicates a high‑severity impact. The EPSS score is not available, so the precise likelihood of exploitation is uncertain, but the lack of an official KEV listing suggests the vulnerability has not yet been widely exploited rendezvous server, which is a realistic scenario for an attacker who can compromise or impersonate a node in the network. Once the malicious server is reachable, the client will crash whenever it to disrupt the operation of the client node. Given the high severity and potential for service disruption, the vulnerability poses a significant risk to peer discovery in libp2p-rendezvous.

Generated by OpenCVE AI on September 11, 2026 at 14:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading libp2p-rendezvous to version 0.17.2 or later, which corrects the integer overflow (CWE-190) and incorrect calculation (CWE-617) vulnerabilities.
  • Configure the client to accept connections only from trusted rendezvous servers and add application‑level validation to reject discovery responses with TTL values that exceed a safe threshold, mitigating potential CWE-190 and CWE-617 exploitation.
  • Monitor for panic events in logs and implement automated restarts or graceful handling to reduce the impact of any remaining service disruptions.

Generated by OpenCVE AI on September 11, 2026 at 14:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Libp2p
Libp2p libp2p-rendezvous
Vendors & Products Libp2p
Libp2p libp2p-rendezvous

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process to panic when computing the expiry timer.
Title libp2p-rendezvous through 0.17.1 Denial of Service via Unbounded Registration TTL in Discovery Responses
Weaknesses CWE-190
CWE-617
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Libp2p Libp2p-rendezvous
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:34.176Z

Reserved: 2026-09-11T01:23:29.845Z

Link: CVE-2026-89146

cve-icon Vulnrichment

Updated: 2026-09-11T18:55:45.903Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T11:16:57.867

Modified: 2026-09-23T17:17:43.997

Link: CVE-2026-89146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:56:29Z

Weaknesses