Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.2
CVE-2026-35480
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for C…
Go Ipld Prime
0.22.0+
HIGH 8.2
CVE-2026-35457
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination coo…
Libp2p
0.17.1+
HIGH 7.5
CVE-2026-35405
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on ho…
Libp2p
0.17.1+
MEDIUM 5.9
CVE-2026-34219
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implement…
Libp2p Gossipsub
0.49.4+
HIGH 7.5
CVE-2026-33040
libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.49.3, the Gossipsub implementation ac…
Libp2p Gossipsub
0.49.3+
HIGH 7.5
CVE-2026-32314
Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementation of Yamux can panic when pr…
Yamux
0.13.10+
HIGH 7.5
CVE-2026-31814
Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a specially crafted WindowUpdate can c…
Yamux
0.13.9+
HIGH 7.5
CVE-2023-40583
libp2p is a networking stack and library modularized out of The IPFS Project, and bundled separately for other tools to use. In go-libp2p, by using s…
Libp2p
0.27.4+
HIGH 7.5
CVE-2023-25568
Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In versions 0.4.0 and 0.5.0, if an attacker is a…
Boxo
Patch available
HIGH 7.5
CVE-2023-23625
go-unixfs is an implementation of a unix-like filesystem on top of an ipld merkledag. Trying to read malformed HAMT sharded directories can cause pan…
Go Unixfs
0.4.3+
HIGH 7.5
CVE-2023-23626
go-bitfield is a simple bitfield package for the go language aiming to be more performant that the standard library. When feeding untrusted user inpu…
Go Bitfield
1.1.0+
HIGH 7.5
CVE-2023-23631
github.com/ipfs/go-unixfsnode is an ADL IPLD prime node that wraps go-codec-dagpb's implementation of protobuf to enable pathing. In versions priot t…
Go Unixfsnode
1.5.2+
HIGH 7.5
CVE-2023-22460
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for C…
Go Ipld Prime
0.19.0+
HIGH 7.5
CVE-2022-2584
The dag-pb codec can panic when decoding invalid blocks.
Go Codec Dagpb
1.3.1+
MEDIUM 5.3
CVE-2022-47547
GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it continuo…
Gossipsub
No fix yet
HIGH 7.5
CVE-2022-23495
go-merkledag implements the 'DAGService' interface and adds two ipld node types, Protobuf and Raw for the ipfs project. A `ProtoNode` may be modified…
Go Merkledag
0.8.1+
HIGH 7.5
CVE-2022-23492
go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted res…
Libp2p
0.18.0+
HIGH 7.5
CVE-2022-23486
libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a vic…
Libp2p
0.45.1+
HIGH 7.5
CVE-2022-23487
js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted…
Libp2p
0.38.0+
HIGH 8.8
CVE-2020-26283
go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, contr…
Go Ipfs
0.8.0+
HIGH 8.1
CVE-2020-26279
go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0-rc1, i…
Go Ipfs
after 0.7.0
HIGH 7.5
CVE-2020-35909
An issue was discovered in the multihash crate before 0.11.3 for Rust. The from_slice parsing code can panic via unsanitized data from a network serv…
Multihash
0.11.3+
HIGH 7.5
CVE-2020-10937
An issue was discovered in IPFS (aka go-ipfs) 0.4.23. An attacker can generate ephemeral identities (Sybils) and leverage the IPFS connection managem…
Ipfs
Mitigation only
CRITICAL 9.8
CVE-2020-12821
Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.
Gossipsub
Patch available