PT-2026-94371 · Libp2P · Libp2P

·

CVE-2026-86040

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libp2p versions prior to 11.0.26
Description @libp2p/floodsub accepts unauthenticated RPC frames on the '/floodsub/1.0.0' endpoint through PeerStreams.attachInboundStream without protobuf element limits. Subsequently, processRpc and processRpcSubOpt synchronously process the subscriptions array without a per-frame cap. This allows a remote peer to send a single bounded-size frame that decodes into millions of empty subscription entries, blocking the event loop and causing CPU exhaustion. Additionally, sending hundreds of thousands of unique-topic SUBSCRIBE entries allocates PeerSet objects in this.topics that are not removed after peer removal or stop, leading to persistent memory growth, out-of-memory termination, and node unavailability. This subscription path bypasses message signature validation and the message-only processing queue.
Recommendations Update to version 11.0.26.

Exploit

Fix

Memory Leak

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86040
GHSA-CVFG-HCF3-GGWV

Affected Products

Libp2P