libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v5hw-cv9c-rpg7 | libp2p-rendezvous: Unbounded rendezvous DISCOVER cookies enable remote memory exhaustion |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1. | |
| Title | libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T17:53:37.355Z
Reserved: 2026-04-02T19:25:52.193Z
Link: CVE-2026-35457
No data.
Status : Received
Published: 2026-04-07T15:17:43.587
Modified: 2026-04-07T15:17:43.587
Link: CVE-2026-35457
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA