PT-2026-94369 · Npm · @Libp2P/Gossipsub

·

CVE-2026-86038

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions @libp2p/gossipsub versions 15.0.0 through 16.0.4
Description In the default StrictSign policy, the validateToRawMessage() function in packages/gossipsub/src/utils/buildRawMessage.ts fails to bind the supplied public key in msg.key to the claimed author in msg.from when the author is an RSA peer ID that does not inline its public key. An unauthenticated attacker can spoof a victim's RSA peer ID by placing it in msg.from, signing the message with their own private key, and providing their own public key in msg.key. This allows the message to be accepted and propagated as if it were authored by the victim. Applications relying on message.from for authorization, accounting, moderation, reputation, or audit logging may process attacker-controlled data under false origin attribution.
Recommendations Update @libp2p/gossipsub to version 16.0.5.

Exploit

Fix

Insufficient Verification of Data Authenticity

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86038
GHSA-C3GV-825Q-FVMP

Affected Products

@Libp2P/Gossipsub