---
id: CVE-2026-34219
title: >-
  libp2p-rust is the official rust language Implementation of the libp2p
  networking stack
summary: >-
  libp2p-rust is the official rust language Implementation of the libp2p
  networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub
  implementation contains a remotely reachable panic in backoff expiry handling.
  After a peer sends…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-190
  - CWE-617
vendor: protocol
product: libp2p-gossipsub
affected:
  - libp2p-gossipsub < 0.49.4
patched:
  - libp2p-gossipsub 0.49.4
published: '2026-03-31'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34219'
references:
  - url: >-
      https://github.com/libp2p/rust-libp2p/security/advisories/GHSA-xqmp-fxgv-xvq5
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00504
epssPercentile: 0.40469
ingestedAt: '2026-07-24T20:38:02.337Z'
---

## Overview

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a crafted PRUNE control message with an attacker-controlled, near-maximum backoff value, the value is accepted and stored as an Instant near the representable upper bound. On a later heartbeat, the implementation performs unchecked Instant + Duration arithmetic (backoff_time + slack), which can overflow and panic with: overflow when adding duration to instant. This issue is reachable from any Gossipsub peer over normal TCP + Noise + mplex/yamux connectivity and requires no further authentication beyond becoming a protocol peer. This issue has been patched in version 0.49.4.

## Affected

- `libp2p-gossipsub < 0.49.4`

## Remediation

Upgrade past the affected range:

- `libp2p-gossipsub 0.49.4`
