CVE-2026-34219Disclosure(protocol / libp2p-gossipsub)

HIGHCVSS 5.9 · MEDIUM

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch protocol libp2p-gossipsub systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a crafted PRUNE control message with an attacker-controlled, near-maximum backoff value, the value is accepted and stored as an Instant near the representable upper bound. On a later heartbeat, the implementation performs unchecked Instant + Duration arithmetic (backoff_time + slack), which can overflow and panic with: overflow when adding duration to instant. This issue is reachable from any Gossipsub peer over normal TCP + Noise + mplex/yamux connectivity and requires no further authentication beyond becoming a protocol peer. This issue has been patched in version 0.49.4.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190CWE-617

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libp2p-gossipsub

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 46 mentions across 15 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 21 signals
  • Technical details provided in 35 signals
  • Disclosure: 28 classified signals
  • General: 4 classified signals
  • Peaked 12d ago at 14 mentions (2026-07-11); latest day: 1
  • 46 total mentions across 15 days

Affected systems

Vendors
Products
libp2p-gossipsub

Deep dive

Activity timeline46 mentions / 15d
0471114Mentions · 2026-07-09: 2Mentions · 2026-07-10: 4Mentions · 2026-07-11: 14Mentions · 2026-07-12: 6Mentions · 2026-07-13: 7Mentions · 2026-07-14: 3Mentions · 2026-07-18: 1Mentions · 2026-07-22: 2Mentions · 2026-07-23: 1Mentions · 2026-07-24: 1Mentions · 2026-08-03: 1Mentions · 2026-08-17: 1Mentions · 2026-08-19: 1Mentions · 2026-08-28: 1Mentions · 2026-09-02: 1PoC Mentioned / Linked · 2026-07-12: 1Active Exploitation · 2026-08-03: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-07-11: 5Patch / Workaround · 2026-07-12: 5Patch / Workaround · 2026-07-13: 4Patch / Workaround · 2026-07-18: 1Patch / Workaround · 2026-08-03: 1Patch / Workaround · 2026-08-17: 1Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-28: 1Technical Details · 2026-07-09: 2Technical Details · 2026-07-10: 1Technical Details · 2026-07-11: 11Technical Details · 2026-07-12: 6Technical Details · 2026-07-13: 5Technical Details · 2026-07-14: 2Technical Details · 2026-07-18: 1Technical Details · 2026-07-22: 2Technical Details · 2026-07-23: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-28: 107-0907-1007-1107-1207-1307-1407-1807-2207-2307-2408-0308-1708-1908-2809-02
Signal classification4 categories
Disclosure
2860.9%
Patch
1123.9%
General
48.7%
False Positive
36.5%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-07-092
Disclosure1Patch1
2026-07-104
Disclosure2False Positive1Patch1
2026-07-1114
Disclosure9General2Patch3
2026-07-126
Disclosure4False Positive1Patch1
2026-07-137
Disclosure4False Positive1General1Patch1
2026-07-143
Disclosure3
2026-07-181
Disclosure1
2026-07-222
Disclosure2
2026-07-231
General1
2026-07-241
Disclosure1
2026-08-031
Patch1
2026-08-171
Patch1
2026-08-191
Patch1
2026-08-281
Patch1
2026-09-021
Disclosure1
Full discourse20 posts
  • Whale Coin Talk@WhaleCoinTalk
    Disclosure

    JUST IN🚨 The Ethereum Foundation used AI agents to hunt for bugs in client software, uncovering a Gossipsub flaw (CVE-2026-34219) that could crash nodes — but says human review remains irreplaceable.🔎

    Post summary

    Ethereum Foundation announced a crash‑inducing Gossipsub flaw (CVE-2026-34219) discovered via AI agents, with no exploit or patch yet available.

    1040195020.9K
    168.0K followersView on X
  • mb.io@multibank_io
    Patch

    Ethereum Foundation set AI agents loose on its protocol code. They found one: a remotely triggerable validator crash, disclosed July 9 as CVE-2026-34219, patched before exploitation. The hard part wasn't finding the bug. It was filtering the AI's confident wrong answers.

    Post summary

    Ethereum Foundation discovered CVE‑2026‑34219, a remotely triggerable validator crash, and patched it before any exploitation was reported.

    2003032.4K
    163.5K followersView on X
  • The Book of Ethereum 📘 booe.eth@Bookof_Eth
    Patch

    EF's AI agents just found a critical DoS in libp2p's gossipsub - the p2p layer every Ethereum consensus client runs on. CVE-2026-34219. Fixed. Disclosed. While everyone debates "AI vs crypto," Ethereum is using AI to harden crypto. This is what serious infrastructure looks like 🙏📖

    Post summary

    EF’s AI agents uncovered a critical denial‑of‑service flaw in Ethereum’s libp2p gossipsub, which has already been fixed and the CVE disclosed.

    430202467
    10.5K followersView on X
  • Manu Sheel Gupta@manusheel
    General

    @ilmeaalim We appreciate the excellent work by the @ethereumfndn Protocol Security team and the researchers who helped identify CVE-2026-34219. From the @libp2p team's perspective, this is a great example of responsible security collaboration.

    Post summary

    The tweet acknowledges the identification of CVE-2026-34219 by the security team and celebrates responsible collaboration, but provides no technical details, patches, exploit code, or evidence of active exploitation.

    16071168
    304 followersView on X
  • Jake@Jakedapoet2k
    Disclosure

    Tìm thấy lỗ hổng triệu đô trong 1 giây, nhưng tốn cả tuần để kiểm chứng. Đây là thực trạng của việc áp dụng AI vào bảo mật tại Ethereum Foundation AI thực sự đã làm được điều không tưởng: nó phát hiện lỗ hổng nghiêm trọng (CVE-2026-34219) trong libp2p chỉ trong tích tắc—điều mà con người có thể mất hàng tháng. Nhưng đi kèm với tốc độ đó là một "cơn bão" báo cáo giả (false positives). Thực tế khắc nghiệt: Đội ngũ Ethereum Foundation tốn nhiều nguồn lực để lọc "nhiễu" từ AI hơn là đi săn lỗi thực tế. AI tạo ra các báo cáo giả thuyết phục đến mức con người phải mất cả tuần chỉ để thẩm định xem đâu là lỗi thật, đâu là dữ liệu ảo.

    Post summary

    The post reports the AI-aided discovery of CVE‑2026‑34219 in libp2p, noting the rapid detection but an accompanying flood of false positives that required extensive verification.

    41090149
    4.5K followersView on X
  • Sherry White@SherryWhit98
    Patch

    Ethereum Patches Critical libp2p Vulnerability An Ethereum infrastructure update patched CVE-2026-34219, a libp2p gossipsub vulnerability that could crash validators — alongside ongoing client performance and sync fixes. #Ethereum #Web3 #Security https://t.co/fZcJIhOyH9

    Post summary

    Ethereum’s infrastructure update applied a patch for CVE‑2026‑34219, a libp2p gossipsub crash vulnerability affecting validators, as part of broader performance and sync fixes.

    0001202.5K
    565 followersView on X
  • Kripto İchizo Terminal@TuncaIchizo
    Disclosure

    💡 Ethereum Foundation, yapay zeka (AI) ajanlarını kullanarak Ethereum kod tabanında uzaktan istismar edilebilir bir hata tespit etti. Protokol güvenlik ekibi, bu deneyde libp2p ağ katmanındaki "gossipsub" bileşeninde CVE-2026-34219 olarak bilinen bir güvenlik açığı buldu. Vakıf, AI ajanlarının bulduğu hatalardan çok, gerçek hataları yanlış pozitiflerden ayırmanın zorluğuna dikkat çekti. - AI tarafından üretilen raporlardaki yanlış pozitiflerin çoğu hata ayıklama sürümlerinde ortaya çıkan, saldırganların erişemeyeceği dahili değerlere dayanan veya teknik olarak doğru ama alakasız olan ispatlardı. - Ekip, bu tür bulguları filtrelemek için "tekrar üretilebilir olmazsa olmamıştır" ilkesini benimsedi ve her hatanın kodu tekrar üreten bağımsız bir kanıtla sunulmasını zorunlu kıldı. - Ethereum Foundation, AI destekli protokol güvenliği araştırmalarını, denetimlerini ve güvenlik açığı tespitini desteklemek için bir hibe turu başlattı. Kaynak: Bitcoin News #Ethereum $ETH

    Post summary

    Ethereum Foundation announced the detection of CVE-2026-34219 in the libp2p gossipsub component, highlighting challenges in separating real bugs from false positives, but provided no PoC, exploit, or mitigation details.

    00080891
    6.4K followersView on X
  • Nicolas St@nico_st_291
    General

    @coinbureau Great reporting. CVE-2026-34219 was against the Cargo package libp2p-gossipsub so non-Rust clients would have been fine though. => Client diversity for the win! Initial blog on the ethereum website: https://blog.ethereum.org/2026/07/09/triage-is-the-product

    Post summary

    The post notes CVE-2026-34219 impacts the Cargo package libp2p-gossipsub, indicating non‑Rust clients are unaffected; no exploit, patch, or active exploitation details are provided.

    00140272
    554 followersView on X
  • Velvet Unicorn@VU_virtuals
    Patch

    $CASHCAT turns over 2.37x market cap in 24h ethereum ai agents find patched libp2p crash cve-2026-34219 apple sues openai over alleged trade-secrets theft meta drops instagram ai image tool after consent backlash robinhood chain records 1b dex volume in 48h

    Post summary

    The mention refers to CVE‑2026‑34219, a patched libp2p crash in Ethereum, but lacks any PoC, exploit code, or active exploitation details.

    10030485
    9.6K followersView on X
  • 雨の夏•₿TC@xiayu912
    Disclosure

    The AI agent really dug out the remote crash vulnerability of CVE-2026-34219 in the Ethereum core code. It was repaired before it made a big fuss, and the efficiency was indeed high. However, the most important thing is not AI to find bugs, but people have to spend a lot of effort to pick out the real thing from a bunch of false positives, and the focus of the work has completely shifted from "discovery" to "judgment".

    Post summary

    The passage announces an AI‑identified remote crash vulnerability (CVE‑2026‑34219) in Ethereum core that has already been patched, while highlighting the difficulty of distinguishing real bugs from false positives.

    2002073
    24.7K followersView on X
  • Cryptonews.com@cryptonews
    Disclosure

    Ethereum AI Security Agents Found Bug That Could Crash Any Node With a Single Message https://cryptonews.com/news/cve-2026-34219-ethereum-gossipsub-vulnerability/?fsp_sid=1331 https://t.co/26yOkCDiGF

    Post summary

    The article reports the discovery of CVE‑2026‑34219, noting that a single malicious message can crash an Ethereum node, but it lacks details on PoC, exploits, patches, or deep technical analysis.

    101112.9K
    148.2K followersView on X
  • 吴说区块链@wublockchain12
    Disclosure

    吴说获悉,以太坊基金会协议安全团队发布文章,总结利用 AI 智能体审计以太坊协议代码的方法与经验。团队表示,AI 智能体已发现包括 libp2p Gossipsub 远程触发崩溃漏洞(CVE-2026-34219)在内的真实安全漏洞,但安全审计的主要瓶颈已从发现漏洞转向验证漏洞真实性。文章认为,AI 更适合作为漏洞搜索工具而非最终判断者,其擅长结合代码与规范发现潜在漏洞、验证安全不变量及生成漏洞复现代码,但也容易将实际不可达的调用链误判为可达、夸大漏洞严重程度,并对需要多个合法步骤按特定顺序触发的漏洞识别能力有限。https://www.wublock123.com/news/ethereum-foundation-ai-audit-shifts-from-finding-to-verifying-vulnerabilities-64326

    Post summary

    The article reports the discovery of a real remote‑triggered crash vulnerability (CVE‑2026‑34219) in Ethereum’s libp2p Gossipsub by an AI audit, noting AI’s limitations but providing no PoC, exploit, or active exploitation evidence.

    400003.0K
    180.8K followersView on X
  • emertgunay.eth@0xemert
    General

    2/ Önce önemli bir ayrım: CVE-2026-34219, Ethereum’un konsensüs kurallarında bulunan bir açık değil. Hata, bazı Ethereum istemcilerinin eşler arası iletişimde kullandığı Rust libp2p’nin Gossipsub bileşeninde tespit edildi. https://t.co/QOMttM9JDU

    Post summary

    The tweet explains that CVE‑2026‑34219 affects the Gossipsub component of Rust libp2p in Ethereum clients, clarifying it is not a consensus‑rule flaw.

    10020214
    1.5K followersView on X
  • Velvet Unicorn@VU_virtuals
    Disclosure

    $HBULL prints 13,810% 24h move within five hours ethereum foundation agents surface cve-2026-34219 validator crash bug BNB chain studio deploys 120k wallet-owning agents on mainnet ASI launchpad runs 250k on-chain agents daily aptos joins OUSD launch backed by 140 firms

    Post summary

    A newly surfaced CVE‑2026‑34219 is identified as a validator crash bug by Ethereum Foundation agents, with no reported exploitation, PoC, or patch details.

    00030484
    9.6K followersView on X
  • 0xGhost👻@0xGhostlovesol
    False Positive

    以太坊基金会 让AI去审计自己的核心代码 AI 真找到一个严重漏洞 一条特制消息就能让验证者崩溃 编号 CVE-2026-34219 已修复 但同一批AI 还交出一大堆"发现" 自信 漂亮 格式工整 只是根本不是漏洞 真的和假的 长得一模一样 一个智能体产出约1,000个候选 顶级筛选里 86% 通过专家复核 但问题不在找 AI 写报告的速度 不管真bug假bug 都同样有说服力 工作量没消失 只是从"找漏洞" 搬到了"判断哪个是真的" 一个发现必须能在真实代码上独立复现 才算数 这一步机器代替不了 基金会给实验起的标题是 甄别本身才是产品 AI 把生成的成本压到接近零 却把验证是否可信的成本抬了上来 当生成变得无限便宜 相信 就成了最贵的那一步 判断 留给你自己

    Post summary

    The post highlights that AI‑based code audits of the Ethereum Foundation produced numerous false positives, underscoring the tool’s limited verification capability, while noting that the real CVE-2026-34219 has already been addressed.

    0102025
    423 followersView on X
  • Mr Black@Mr_Black_Lab
    Disclosure

    Ethereum Foundation ran AI agents against its own protocol code. Real bug found — one crafted message could crash any validator. CVE-2026-34219. The agents also handed back ~1,000 confident but fake findings. Finding it wasn't the hard part. Proving it was real, was

    Post summary

    Ethereum Foundation announced discovery of CVE-2026-34219, a crafted message that crashes validators, confirming the vulnerability but offering no exploit material or patch guidance.

    0003069
    390 followersView on X
  • Diario฿itcoin@DiarioBitcoin
    False Positive

    🚨 La Fundación Ethereum alerta sobre la detección de fallas en su red por agentes de IA. Se señala que el verdadero desafío ahora es el triaje de reportes. Los agentes identificaron vulnerabilidades reales, como el CVE-2026-34219. Sin embargo, muchos hallazgos resultan ser falsos positivos. Ethereum enfatiza que la IA debe ser una herramienta y no la autoridad final en la seguridad. El juicio humano es fundamental para validar los hallazgos.

    Post summary

    Ethereum warns that AI‑based vulnerability detection yields many false positives and emphasizes the need for human validation.

    110101.1K
    213.0K followersView on X
  • Cripto Matica@CriptoMatica
    Patch

    3/10 Hubo un resultado concreto: una caída activable de forma remota en gossipsub de libp2p, parte de la capa P2P usada por clientes de consenso. Fue corregida y divulgada como CVE-2026-34219. La IA ayudó a encontrarla; la validación la convirtió en hallazgo. https://t.co/GOuJC8FB9J

    Post summary

    A remote crash in libp2p’s gossipsub was discovered and patched, with the vulnerability disclosed as CVE-2026-34219.

    1001027
    148 followersView on X
  • ᙢinus ᙡells@MinusWells
    Disclosure

    Ethereum Foundation researchers used coordinated AI agents to find real protocol-code bugs. One result became CVE-2026-34219, a remotely triggered panic in libp2p gossipsub used by consensus clients. https://t.co/fOspY8L6ZU

    Post summary

    Ethereum Foundation researchers identified CVE‑2026‑34219, a remotely triggered panic in the libp2p gossipsub peer‑to‑peer protocol used by consensus clients, without any mention of exploit, active exploitation, or patch availability.

    00020761
    26.0K followersView on X
  • Velvet Unicorn@VU_virtuals
    Disclosure

    $SCAM turns over 3.3x market cap during 684% daily move bonzo loses 9m after supra oracle verifier flaw ethereum ai agents flag libp2p crash cve-2026-34219 robinhood prepares agent-connected crypto accounts with real-time p&l empery digital sells 1,400 BTC for ai data centers

    Post summary

    CVE-2026-34219 has been identified as a libp2p crash in Ethereum AI agents; the entry lacks any proof‑of‑concept, exploitation details, or patch information.

    00020892
    9.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprotocollibp2p-gossipsub-rust-

Explore more