PT-2026-94371 · Libp2P · Libp2P
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libp2p versions prior to 11.0.26
Description
@libp2p/floodsub accepts unauthenticated RPC frames on the '/floodsub/1.0.0' endpoint through
PeerStreams.attachInboundStream without protobuf element limits. Subsequently, processRpc and processRpcSubOpt synchronously process the subscriptions array without a per-frame cap. This allows a remote peer to send a single bounded-size frame that decodes into millions of empty subscription entries, blocking the event loop and causing CPU exhaustion. Additionally, sending hundreds of thousands of unique-topic SUBSCRIBE entries allocates PeerSet objects in this.topics that are not removed after peer removal or stop, leading to persistent memory growth, out-of-memory termination, and node unavailability. This subscription path bypasses message signature validation and the message-only processing queue.Recommendations
Update to version 11.0.26.
Exploit
Fix
Memory Leak
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Libp2P