libp2p vulnerabilities
CVEs whose affected-version data names the libp2p package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-73568High· 7.5py-libp2p is the Python implementation of the libp2p networking stack
py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly…
▾ Twilightlibp2p · libp2pEPSS 0.41%via NVD
GHSA-hmj8-5xmh-5573High· 7.5libp2p: yamux connection DoS via oversized data frame
libp2p: yamux connection DoS via oversized data frame
▾ Twilightlibp2p · libp2pvia GHSA
CVE-2025-29606Medium· 4.3py-libp2p is vulnerable to DoS attacks through use of large RSA keys
py-libp2p is vulnerable to DoS attacks through use of large RSA keys
▾ Sunlitlibp2p · libp2pEPSS 0.33%via OSV