libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Protocol
Protocol libp2p |
|
| CPEs | cpe:2.3:a:protocol:libp2p:*:*:*:*:*:rust:*:* | |
| Vendors & Products |
Protocol
Protocol libp2p |
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libp2p
Libp2p rust-libp2p |
|
| Vendors & Products |
Libp2p
Libp2p rust-libp2p |
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1. | |
| Title | libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T17:53:37.355Z
Reserved: 2026-04-02T19:25:52.193Z
Link: CVE-2026-35457
Updated: 2026-04-07T17:53:25.830Z
Status : Analyzed
Published: 2026-04-07T15:17:43.587
Modified: 2026-04-24T13:32:56.967
Link: CVE-2026-35457
No data.