Protocol's vulnerability footprint centers on a focused set of distributed systems and peer-to-peer networking libraries, including libp2p, go-ipfs, and related IPLD and gossip-protocol implementations, that sit within a growing ecosystem of decentralized applications and infrastructure. The observed weakness classes recur around resource-management boundaries: uncontrolled resource consumption, allocation without limits or throttling, integer overflows, and insufficient exception handling reflect the parser and network-message-handling complexity inherent to protocol implementations that must operate in adversarial peer-to-peer environments. While the product portfolio is comparatively narrow, these libraries occupy a prominent position in the distributed systems and blockchain landscape, making their stability and resource efficiency significant to defenders tracking supply-chain dependencies and denial-of-service vectors. Defenders should monitor this vendor's advisories closely, particularly for deployments where peer-to-peer mesh networks are exposed to untrusted participants; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Protocol over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35457HIGH libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthe | Apr 7, 2026 | 8.2 | 28 | NO | NO |
CVE-2026-34219MEDIUM libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reach | Mar 31, 2026 | 5.9 | 28 | NO | NO |
CVE-2026-35405HIGH libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on how many namespaces a single peer | Apr 7, 2026 | 7.5 | 26 | NO | NO |
CVE-2020-26283HIGH go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, control characters are not escaped f | Mar 24, 2021 | 8.8 | 26 | NO | NO |
CVE-2023-22460HIGH go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for b | Jan 4, 2023 | 7.5 | 25 | NO | NO |
CVE-2022-23495HIGH go-merkledag implements the 'DAGService' interface and adds two ipld node types, Protobuf and Raw for the ipfs project. A `ProtoNode` may be modified in such a way as to cause vari | Dec 8, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-23492HIGH go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted resource exhaustion attacks. These | Dec 8, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-23487HIGH js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted resource exhaustion attacks. T | Dec 7, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-23486HIGH libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a victim node to allocate a large nu | Dec 7, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-26279HIGH go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0-rc1, it is possible for path traversa | Mar 24, 2021 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Protocol.
Media articles that mention a CVE ID that affects a product developed by Protocol — matched by CVE ID, not by vendor name.