Vulnerability Description
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Protocol | Libp2P | < 0.17.1 |
Related Weaknesses (CWE)
References
- https://github.com/libp2p/rust-libp2p/security/advisories/GHSA-v5hw-cv9c-rpg7ExploitVendor Advisory
FAQ
What is CVE-2026-35457?
CVE-2026-35457 is a vulnerability with a CVSS score of 8.2 (HIGH). libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can re...
How severe is CVE-2026-35457?
CVE-2026-35457 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-35457?
Check the references section above for vendor advisories and patch information. Affected products include: Protocol Libp2P.