7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
0.001 Low
EPSS
Percentile
44.0%
go-libp2p is vulnerable to Denial Of Service (DoS). The vulnerability exists during the Noise handshake and the libp2p x509 extension verification step which allows an attacker to use large RSA keys causing resource exhaustion.
github.com/advisories/GHSA-876p-8259-xjgg
github.com/golang/go/commit/2350afd2e8ab054390e284c95d5b089c142db017
github.com/golang/go/issues/61460
github.com/libp2p/go-libp2p/commit/0cce607219f3710addc7e18672cffd1f1d912fbb
github.com/libp2p/go-libp2p/commit/445be526aea4ee0b1fa5388aa65d32b2816d3a00
github.com/libp2p/go-libp2p/commit/e30fcf7dfd4715ed89a5e68d7a4f774d3b9aa92d
github.com/libp2p/go-libp2p/pull/2454
github.com/libp2p/go-libp2p/security/advisories/GHSA-876p-8259-xjgg
github.com/quic-go/quic-go/pull/4012