VulnSea

libp2p has 10 CVEs on record between 2023 and 2026. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 5. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-400 (4) and CWE-770 (3). Most affected products: libp2p (3), @libp2p/gossipsub (2), js-libp2p (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
8 prev 0

Products

  • libp2p 3
  • @libp2p/gossipsub 2
  • js-libp2p 2
  • go-libp2p 1
  • libp2p-rendezvous 1
  • rust-libp2p 1
10
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

libp2p vulnerabilities

CVEs affecting libp2p, newest first. Open any entry for full detail, references, and exploit status.

10 CVEsRSS

CVE-2026-86040High· 7.5
4d ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floodsub/1.0.0 through PeerStreams.attachInboundStream in packages/floodsub/src/peer-streams.…

Twilightlibp2p · js-libp2pEPSS 0.37%via NVD
CVE-2026-86039High· 8.2
4d ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerR…

Twilightlibp2p · js-libp2pEPSS 0.18%via NVD
CVE-2026-86038High· 7.5PoC
4d ago

libp2p is a JavaScript implementation of the libp2p networking stack

libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies …

Midnightlibp2p · @libp2p/gossipsubEPSS 0.16%via NVD
CVE-2026-61544High· 8.2PoC
6d ago

libp2p-rust is the official Rust language implementation of the libp2p networking stack

libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a remote peer presented a valid short-lived libp2p TLS certificate an…

Midnightlibp2p · rust-libp2pEPSS 0.23%via NVD
CVE-2026-89146High· 7.5PoC
1w ago

libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow

libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL…

Midnightlibp2p · libp2p-rendezvousEPSS 0.43%via NVD
CVE-2026-73568High· 7.5
1mo ago

py-libp2p is the Python implementation of the libp2p networking stack

py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly…

Twilightlibp2p · libp2pEPSS 0.41%via NVD
GHSA-hmj8-5xmh-5573High· 7.5
1mo ago

libp2p: yamux connection DoS via oversized data frame

libp2p: yamux connection DoS via oversized data frame

Twilightlibp2p · libp2pvia GHSA
CVE-2026-49866High· 7.5
2mo ago

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays

Twilightlibp2p · @libp2p/gossipsubEPSS 0.63%via GHSA
CVE-2025-29606Medium· 4.3
1y ago

py-libp2p is vulnerable to DoS attacks through use of large RSA keys

py-libp2p is vulnerable to DoS attacks through use of large RSA keys

Sunlitlibp2p · libp2pEPSS 0.33%via OSV
CVE-2023-39533High· 7.5
3y ago

go-libp2p is the Go implementation of the libp2p Networking Stack

go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verifi…

Twilightlibp2p · go-libp2pEPSS 1.5%via NVD
libp2p vulnerabilities (CVEs) · VulnSea