CVE-2026-34219 details a remotely reachable panic vulnerability in the libp2p-rust Gossipsub implementation, affecting versions prior to 0.49.4. An attacker can trigger a denial of service by sending a crafted PRUNE control message with a specific backoff value, causing an Instant overflow during heartbeat processing. This high-severity vulnerability (CVSS 8.2) is easily exploitable over the network without authentication, leading to a system panic. Currently, there is no evidence of active exploitation or public exploit code, though the issue has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.49.4CPE matchmatch criteria | cpe:2.3:a:protocol:libp2p-gossipsub:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.