Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.67% | — | Libp2p FloodsubAI | 17/9/2026 | 24/9/2026 | libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC frames on /floodsub/1.0.0 through PeerStreams.attachInboundStream in packages/floodsub/src/peer-streams.ts without protobuf element limits, then processRpc and processRpcSubOpt in… | |
| Pendiente de análisis | Alta (8.2) | 0.27% | — | Libp2pAILibp2p Peer-storeAI | 17/9/2026 | 24/9/2026 | libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in packages/peer-store/src/index.ts uses consumePeerRecord to verify a RecordEnvelope signature but does not require PeerRecord.peerId in the signed payload to equal the signer peer ID derived by… | |
| Pendiente de análisis | Alta (7.5) | 0.19% | — | Libp2p GossipsubAI | 17/9/2026 | 30/9/2026 | libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies a signature with attacker-controlled msg.key but skips binding that key to… | |
| Pendiente de análisis | Alta (8.2) | 0.28% | — | Libp2p QuicAILibp2p TLSAI | 15/9/2026 | 30/9/2026 | libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic could panic during an inbound QUIC handshake when a remote peer presented a valid short-lived libp2p TLS certificate and delayed the final TLS 1.3 handshake fragment until after the certificate… | |
| Aplazada | Alta (8.7) | 0.63% | — | Libp2p RendezvousAI | 11/9/2026 | 23/9/2026 | libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process to panic when computing the expiry… | |
| Aplazada | Alta (7.5) | 0.61% | — | Libp2pAILibp2p Circuit Relay V2AI | 24/8/2026 | 9/9/2026 | libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer can repeatedly send valid RESERVE… | |
| Aplazada | Alta (7.5) | 0.49% | — | Py-libp2pAI | 13/8/2026 | 18/9/2026 | py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly() before validating it against MAX_WINDOW_SIZE or checking whether stream_id… | |
| Aplazada | Alta (7.5) | 0.49% | — | Klever-goAIGo-libp2p-pubsubAI | 7/8/2026 | 9/9/2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered by a protobuf Transaction whose embedded RawData sub-message is omitted. This omission causes RawData to decode to nil. Every transaction gossiped on the Klever-Go P2P… | |
| Aplazada | Alta (7.5) | 0.63% | — | Libp2p GossipsubAI | 8/7/2026 | 10/7/2026 | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLimits set maxIhaveMessageIDs and maxIwantMessageIDs to Infinity, allowing oversized IHAVE and IWANT control message arrays in message/decodeRpc.ts and gossipsub.ts to synchronously iterate roughly… | |
| Aplazada | Alta (7.5) | 0.46% | — | Libp2p GossipsubAI | 10/6/2026 | 23/7/2026 | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an unauthenticated single peer to exhaust the Node.js heap of any gossipsub node with default options. This issue has been patched in version 15.0.23. | |
| Aplazada | Alta (7.5) | 0.50% | — | Libp2pAILibp2p KAD DHTAI | 10/6/2026 | 23/7/2026 | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote peer can exhaust the disk storage of any @libp2p/kad-dht node running in server mode by sending an unbounded stream of PUT_VALUE messages whose keys bypass all content validation. No credentials, no… | |
| Aplazada | Media (5.3) | 0.51% | — | NimiqAINimiq Network-libp2pAI | 10/6/2026 | 23/7/2026 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-libp2p handles kad get-record query progress in handle_dht_get (network-libp2p/src/swarm.rs). Prior to version 1.4.0, when a peer returns a FoundRecord, the code verifies the record via… | |
| Analizada | Alta (8.2) | 0.42% | — | Protocol Libp2p | 7/4/2026 | 17/6/2026 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1. | |
| Analizada | Alta (7.5) | 0.49% | — | Protocol Libp2p | 7/4/2026 | 17/6/2026 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on how many namespaces a single peer can register. A malicious peer can just keep registering unique namespaces in a loop and the server happily accepts every single one… | |
| Analizada | Alta (8.2) | 0.50% | — | Protocol Libp2p-gossipsub | 31/3/2026 | 24/7/2026 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a crafted PRUNE control message with an attacker-controlled, near-maximum backoff… | |
| Analizada | Alta (8.7) | 0.54% | — | Protocol Libp2p-gossipsub | 20/3/2026 | 17/6/2026 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.49.3, the Gossipsub implementation accepts attacker-controlled PRUNE backoff values and may perform unchecked time arithmetic when storing backoff state. A specially crafted PRUNE control message with an… | |
| Aplazada | Media (4.3) | 0.33% | — | Py-libp2pAI | 14/7/2025 | 17/6/2026 | py-libp2p before 0.2.3 allows a peer to cause a denial of service (resource consumption) via a large RSA key. | |
| Aplazada | Media (5.3) | 0.21% | — | IpfsAIGo-libp2p-kad-dhtAI | 25/10/2024 | 17/6/2026 | The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information for content (i.e., information about who holds the content) to be stored by peers whose peer IDs have a small DHT distance from the content ID. This allows an attacker to censor content by generating… | |
| Aplazada | Alta (7.5) | 0.76% | — | Libp2pAIProtocol YamuxAI | 1/5/2024 | 17/6/2026 | Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. The Rust implementation of the Yamux stream multiplexer uses a vector for pending frames. This vector is not bounded in length. Every time the Yamux protocol requires sending of a new frame, this frame gets appended to this vector. This… | |
| Modificada | Alta (7.5) | 0.95% | — | Protocol Libp2p | 25/8/2023 | 17/6/2026 | libp2p is a networking stack and library modularized out of The IPFS Project, and bundled separately for other tools to use. In go-libp2p, by using signed peer records a malicious actor can store an arbitrary amount of data in a remote node’s memory. This memory does not get garbage collected and so the victim can run… | |
| Modificada | Alta (7.5) | 1.5% | — | Go-libp2p | 8/8/2023 | 1/9/2026 | go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verification of the large key. This vulnerability is present in the core/crypto module… | |
| Modificada | Alta (7.5) | 1.0% | — | Protocol Libp2p | 8/12/2022 | 17/6/2026 | go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can cause the allocation of large amounts of memory,… | |
| Modificada | Alta (7.5) | 0.71% | — | Protocol Libp2p | 7/12/2022 | 17/6/2026 | js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can cause the allocation of large amounts of… | |
| Modificada | Alta (7.5) | 0.71% | — | Protocol Libp2p | 7/12/2022 | 17/6/2026 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a victim node to allocate a large number of small memory chunks, which can ultimately lead to the victim’s process running out of memory and thus getting killed by its… | |
| Modificada | Alta (7.4) | 0.50% | — | Chainsafe Js-libp2p-noise | 17/3/2022 | 17/6/2026 | `@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `@chainsafe/libp2p-noise` before 4.1.2 and 5.0.3 does not correctly validate signatures during the handshake process. This may allow a man-in-the-middle to pose as other peers and get those peers… |