libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libp2p
Libp2p rust-libp2p |
|
| Vendors & Products |
Libp2p
Libp2p rust-libp2p |
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1. | |
| Title | libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-04-07T14:22:19.941Z
Updated: 2026-04-07T17:53:37.355Z
Reserved: 2026-04-02T19:25:52.193Z
Link: CVE-2026-35457
Updated: 2026-04-07T17:53:25.830Z
Status : Awaiting Analysis
Published: 2026-04-07T15:17:43.587
Modified: 2026-04-08T21:27:15.610
Link: CVE-2026-35457
No data.