CVE-2026-35457Disclosure(protocol / libp2p)

LOWCVSS 8.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch protocol libp2p systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libp2p

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-07)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
libp2p

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-05: 1Mentions · 2026-04-07: 2Patch / Workaround · 2026-04-05: 1Technical Details · 2026-04-05: 1Technical Details · 2026-04-07: 104-0504-07
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-051
Disclosure1
2026-04-072
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-35457 libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without boun… https://www.cve.org/CVERecord?id=CVE-2026-35457 ----- Traducción: CVE-2026-35457 lib… http://infoflow.cloud`

    Post summary

    The post merely references a CVE record for libp2p-rust with minimal details, lacking any PoC, exploit, patch, or active exploitation evidence.

    0000032
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35457 libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without boun… https://www.cve.org/CVERecord?id=CVE-2026-35457

    Post summary

    The snippet announces CVE-2026-35457, describing a flaw in libp2p-rust’s rendezvous server where pagination cookies are mishandled before v0.17.1, but provides no PoC, exploit, active‑use, or patch information.

    00000208
    57.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A remote memory exhaustion vulnerability (CVE-2026-35457) in `libp2p-rendezvous` can lead to denial of service. Monitor for official patches. #libp2p #DoS #infosec https://www.pulsepatch.io/posts/cve-2026-35457-libp2p-rendezvous-memory-exhaustion

    Post summary

    The post announces a remote memory exhaustion denial‑of‑service vulnerability (CVE‑2026‑35457) in libp2p‑rendezvous and advises monitoring for official vendor patches.

    0000039
    4 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprotocollibp2p-rust-

Explore more