Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.19% | — | Libp2p GossipsubAI | 17/9/2026 | 30/9/2026 | libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies a signature with attacker-controlled msg.key but skips binding that key to… | |
| Aplazada | Alta (7.5) | 0.63% | — | Libp2p GossipsubAI | 8/7/2026 | 10/7/2026 | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLimits set maxIhaveMessageIDs and maxIwantMessageIDs to Infinity, allowing oversized IHAVE and IWANT control message arrays in message/decodeRpc.ts and gossipsub.ts to synchronously iterate roughly… | |
| Aplazada | Alta (7.5) | 0.46% | — | Libp2p GossipsubAI | 10/6/2026 | 23/7/2026 | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an unauthenticated single peer to exhaust the Node.js heap of any gossipsub node with default options. This issue has been patched in version 15.0.23. | |
| Analizada | Alta (8.2) | 0.50% | — | Protocol Libp2p-gossipsub | 31/3/2026 | 24/7/2026 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a crafted PRUNE control message with an attacker-controlled, near-maximum backoff… | |
| Analizada | Alta (8.7) | 0.54% | — | Protocol Libp2p-gossipsub | 20/3/2026 | 17/6/2026 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.49.3, the Gossipsub implementation accepts attacker-controlled PRUNE backoff values and may perform unchecked time arithmetic when storing backoff state. A specially crafted PRUNE control message with an… | |
| Modificada | Media (5.3) | 0.53% | — | Protocol Gossipsub | 19/12/2022 | 17/6/2026 | GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it continuously misbehaves by never forwarding topic messages. | |
| Modificada | Crítica (9.8) | 1.9% | — | Protocol Gossipsub | 7/7/2020 | 17/6/2026 | Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack. |