libp2p has 10 CVEs on record between 2023 and 2026. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 5. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-400 (4) and CWE-770 (3). Most affected products: libp2p (3), @libp2p/gossipsub (2), js-libp2p (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 8 prev 0
Products
- libp2p 3
- @libp2p/gossipsub 2
- js-libp2p 2
- go-libp2p 1
- libp2p-rendezvous 1
- rust-libp2p 1
Worst active — by depth score
CVE-2026-61544High· 8.2libp2p-rust is the official Rust language implementation of the libp2p networking stack57CVE-2026-86038High· 7.5libp2p is a JavaScript implementation of the libp2p networking stack53CVE-2026-89146High· 7.5libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow53CVE-2026-86039High· 8.2libp2p is a JavaScript implementation of the libp2p networking stack45CVE-2023-39533High· 7.5go-libp2p is the Go implementation of the libp2p Networking Stack42
libp2p vulnerabilities
CVEs affecting libp2p, newest first. Open any entry for full detail, references, and exploit status.
10 CVEsRSS
CVE-2026-86040High· 7.5libp2p is a JavaScript implementation of the libp2p networking stack
libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floodsub/1.0.0 through PeerStreams.attachInboundStream in packages/floodsub/src/peer-streams.…
CVE-2026-86039High· 8.2libp2p is a JavaScript implementation of the libp2p networking stack
libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerR…
CVE-2026-86038High· 7.5PoClibp2p is a JavaScript implementation of the libp2p networking stack
libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies …
CVE-2026-61544High· 8.2PoClibp2p-rust is the official Rust language implementation of the libp2p networking stack
libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a remote peer presented a valid short-lived libp2p TLS certificate an…
CVE-2026-89146High· 7.5PoClibp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow
libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL…
CVE-2026-73568High· 7.5py-libp2p is the Python implementation of the libp2p networking stack
py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly…
GHSA-hmj8-5xmh-5573High· 7.5libp2p: yamux connection DoS via oversized data frame
libp2p: yamux connection DoS via oversized data frame
CVE-2026-49866High· 7.5libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays
CVE-2025-29606Medium· 4.3py-libp2p is vulnerable to DoS attacks through use of large RSA keys
py-libp2p is vulnerable to DoS attacks through use of large RSA keys
CVE-2023-39533High· 7.5go-libp2p is the Go implementation of the libp2p Networking Stack
go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verifi…