Libp2p is a modular peer-to-peer networking library that powers decentralized applications and blockchain systems, with its primary exposure surfacing in the Go implementation and related protocol extensions. The recurring vulnerability patterns center on resource-exhaustion conditions, cryptographic-signature verification gaps, and uninitialized resource handling—weakness classes that reflect the protocol-coordination and cryptographic demands of a distributed networking stack. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libp2p over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36443CRITICAL An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust. An uninitialized buffer is passed to AsyncRead::poll_read(), which is a user-provided trait function. | Aug 8, 2021 | 9.8 | 29 | NO | NO |
CVE-2019-15545HIGH An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures. | Aug 26, 2019 | 7.5 | 23 | NO | NO |
CVE-2023-39533HIGH go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion a | Aug 8, 2023 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libp2p.
Media articles that mention a CVE ID that affects a product developed by Libp2p — matched by CVE ID, not by vendor name.