Where
-Infinity
0

go/github.com/ipld/go-ipld-primego-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headers

Risk 36
Severity
6.2
First published (updated )

rust/libp2p-rendezvouslibp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion

Risk 54
Severity
8.2
First published (updated )

rust/libp2p-rendezvouslibp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers

Risk 43
Severity
7.5
First published (updated )

rust/libp2p-gossipsublibp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow

Risk 43
Severity
8.2
First published (updated )

rust/libp2p-gossipsublibp2p-rust: Gossipsub PRUNE.backoff Duration Overflow

Risk 33
Severity
8.7
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

cargo/yamuxYamux remote Panic via malformed Data frame with SYN set and len = 262145

Risk 33
Severity
8.7
EPSS
0.05%
First published (updated )

rust/yamuxYamux remote Panic via malformed WindowUpdate credit

Risk 33
Severity
8.7
EPSS
0.08%
First published (updated )

go/github.com/libp2p/go-libp2plibp2p nodes vulnerable to OOM attack

Risk 44
Severity
7.5
First published (updated )

protocol Boxo GoBoxo bitswap/server: DOS unbounded persistent memory leak

Risk 55
Severity
8.2
First published (updated )

protocol Go-unixfs GoDenial of service in HAMT Decoding in go-unixfs

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

protocol Go-bitfield GoDenial of service when feeding malformed size arguments in go-bitfield

Risk 43
Severity
7.5
First published (updated )

protocol Go-unixfsnode GoHAMT Decoding Panics in github.com/ipfs/go-unixfsnode

Risk 43
Severity
7.5
First published (updated )

go/github.com/ipld/go-ipld-primego-ipld-prime json codec may panic if asked to encode bytes

Risk 45
Severity
7.5
First published (updated )

protocol Go-codec-dagpb GoPanic when decoding invalid blocks in github.com/ipld/go-codec-dagpb

Risk 43
Severity
7.5
First published (updated )

protocol GossipsubGossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be…

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

protocol Go-merkledagProtoNode may be modified such that common method calls may panic in ipfs/go-merkledag

Risk 43
Severity
7.5
First published (updated )

protocol Libp2p Gogo-libp2p denial of service vulnerability from lack of resource management

Risk 43
Severity
7.5
First published (updated )

protocol Libp2p Node.jslibp2p denial of service vulnerability from lack of resource management

Risk 43
Severity
7.5
First published (updated )

protocol Libp2p Rustlibp2p-rust denial of service vulnerability from lack of resource management

Risk 43
Severity
7.5
First published (updated )

protocol Go-ipfsControl character injection in console output

Risk 79
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

protocol Go-ipfsPath traversal

Risk 60
Severity
8.1
First published (updated )

protocol Multihash RustAn issue was discovered in the multihash crate before 0.11.3 for Rust. The from_slice parsing code c…

Risk 44
Severity
7.8
First published (updated )

go/github.com/ipfs/go-ipfsAn issue was discovered in IPFS (aka go-ipfs) 0.4.23. An attacker can generate ephemeral identities …

Risk 45
Severity
7.5
First published (updated )

protocol GossipsubGossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil at…

Risk 86
Severity
9.8
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203