← Zurück zur CVE-Suche

CVE-2026-34063

Nimiq-s network-libp2p

Beschreibung

Nimiq-s network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `ConnectionHandler` state machine. the handler assumes there is at most one inbound and one outbound discovery substream per connection. if a remote peer opens/negotiate the discovery protocol substream a second time on the same connection, the handler hits a `panic!(\-Inbound already connected\-)` / `panic!(\-Outbound already connected\-)` path instead of failing closed. This causes a remote crash of the networking task (swarm), taking the node-s p2p networking offline until restart. The patch for this vulnerability is formally released as part of v1.3.0. No known workarounds are available.

CVSS 7.5EPSS 0.35200000000000004%Risiko 0.77
Quelle öffnen
Veröffentlicht
2026-04-22 20:16:40
Betroffene Versionen
<1.3.0
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H