libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1. | |
| Title | libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T17:53:37.355Z
Reserved: 2026-04-02T19:25:52.193Z
Link: CVE-2026-35457
Updated: 2026-04-07T17:53:25.830Z
Status : Received
Published: 2026-04-07T15:17:43.587
Modified: 2026-04-07T15:17:43.587
Link: CVE-2026-35457
No data.
OpenCVE Enrichment
No data.