OVERVIEW CVE-2026-35457 is a denial-of-service vulnerability in libp2p-rust versions prior to 0.17.1, the official Rust implementation of the libp2p networking stack. The flaw exists in the rendezvous server component, which fails to enforce limits on pagination cookies stored during DISCOVER requests, enabling unbounded memory consumption. SEVERITY The vulnerability carries a CVSS 3.1 score of 8.2 (HIGH) with a network-based attack vector requiring no authentication, low complexity, and no user interaction. An unauthenticated remote peer can exploit this by repeatedly issuing DISCOVER requests to trigger uncontrolled memory growth on affected servers. The impact is primarily availability-focused, with secondary integrity concerns, though confidentiality is not affected. EXPLOITATION STATUS This vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no active exploitation activity. The EPSS score of 0.000520000 indicates relatively low probability of exploitation in the wild compared to other CVEs. Community attention appears limited, with the vulnerability marked as inactive on threat tracking lists, though patching to version 0.17.1 or later is recommended for affected libp2p-rust deployments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.17.1CPE matchmatch criteria | cpe:2.3:a:protocol:libp2p:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.