PT-2026-34543 · Nimiq · Network-Libp2P
Published
2026-04-22
·
Updated
2026-04-22
·
CVE-2026-34062
CVSS v3.1
5.3
Medium
| AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0,
MessageCodec::read request and read response call read to end() on inbound substreams, so a remote peer can send only a partial frame and keep the substream open. because Behaviour::new also sets with max concurrent streams(1000), the node exposes a much larger stalled-slot budget than the library default. The patch for this vulnerability is formally released as part of v1.3.0. No known workarounds are available.Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Network-Libp2P