CVE-2022-23495 is a denial-of-service vulnerability affecting the go-merkledag library, specifically within its implementation of the 'DAGService' for IPFS. Malicious manipulation of a ProtoNode can lead to unencodeable states, causing common method calls to panic due to the inability to return errors. With a CVSS score of 7.5 (HIGH), this vulnerability can be triggered remotely without authentication or user interaction, resulting in high availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.4.0, < 0.8.1CPE matchmatch criteria | cpe:2.3:a:protocol:go-merkledag:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.