{"id":"CVE-2026-34219","title":"libp2p-rust is the official rust language Implementation of the libp2p networking stack","summary":"libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-190","CWE-617"],"vendor":"protocol","product":"libp2p-gossipsub","affected":["libp2p-gossipsub < 0.49.4"],"patched":["libp2p-gossipsub 0.49.4"],"published":"2026-03-31","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-34219","references":[{"url":"https://github.com/libp2p/rust-libp2p/security/advisories/GHSA-xqmp-fxgv-xvq5","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00561,"epssPercentile":0.45486,"ingestedAt":"2026-07-24T20:38:02.337Z","slug":"CVE-2026-34219","body":"## Overview\n\nlibp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a crafted PRUNE control message with an attacker-controlled, near-maximum backoff value, the value is accepted and stored as an Instant near the representable upper bound. On a later heartbeat, the implementation performs unchecked Instant + Duration arithmetic (backoff_time + slack), which can overflow and panic with: overflow when adding duration to instant. This issue is reachable from any Gossipsub peer over normal TCP + Noise + mplex/yamux connectivity and requires no further authentication beyond becoming a protocol peer. This issue has been patched in version 0.49.4.\n\n## Affected\n\n- `libp2p-gossipsub < 0.49.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `libp2p-gossipsub 0.49.4`","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}