{"apiVersion":"1.0","identifier":"CVE-2026-73568","description":"py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly() before validating it against MAX_WINDOW_SIZE or checking whether stream_id exists. A peer that completes the standard Noise handshake can send a 12-byte frame declaring a 0xFFFFFFFF body and then withhold the body, causing the sequential yamux read loop used by the default new_host() configuration to block and preventing every stream on that connection from making progress. No fixed version is available as of this review.","publishedAt":"2026-08-13T18:18:19","lastModifiedAt":"2026-08-13T19:17:35","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73568","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","epssProbability":0.00351,"riskScore":0.77,"affectedProduct":"py-libp2p","affectedVersions":"<=0.7.0","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-73568","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-73568","en":"https://www.redsauce.net/en/cves/CVE-2026-73568","fr":"https://www.redsauce.net/fr/cves/CVE-2026-73568","pt":"https://www.redsauce.net/pt/cves/CVE-2026-73568","de":"https://www.redsauce.net/de/cves/CVE-2026-73568","sk":"https://www.redsauce.net/sk/cves/CVE-2026-73568","el":"https://www.redsauce.net/el/cves/CVE-2026-73568"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-73568"}}