I2pd is a lightweight, open-source implementation of the I2P anonymity network, deployed primarily as a single focused product for participants seeking privacy-oriented networking. Its vulnerability profile centers on memory-safety issues, particularly out-of-bounds read conditions that arise from parsing and buffer-handling in the network protocol implementation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by I2pd over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17066HIGH The (1) i2pd before 2.17 and (2) kovri pre-alpha implementations of the I2P routing protocol do not properly handle Garlic DeliveryTypeTunnel packets, which allows remote attackers | Dec 5, 2017 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by I2pd.
Media articles that mention a CVE ID that affects a product developed by I2pd — matched by CVE ID, not by vendor name.