Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.2 CVE-2026-35480 go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for C… Go Ipld Prime 0.22.0+ Fix from $1,6002026-04-07 HIGH 8.2 CVE-2026-35457 libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination coo… Libp2p 0.17.1+ Fix from $1,9502026-04-07 HIGH 7.5 CVE-2026-35405 libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on ho… Libp2p 0.17.1+ Fix from $1,9502026-04-07 MEDIUM 5.9 CVE-2026-34219 libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implement… Libp2p Gossipsub 0.49.4+ Fix from $1,6002026-03-31 HIGH 7.5 CVE-2026-33040 libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.49.3, the Gossipsub implementation ac… Libp2p Gossipsub 0.49.3+ Fix from $1,9502026-03-20 HIGH 7.5 CVE-2026-32314 Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementation of Yamux can panic when pr… Yamux 0.13.10+ Fix from $1,9502026-03-16 HIGH 7.5 CVE-2026-31814 Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a specially crafted WindowUpdate can c… Yamux 0.13.9+ Fix from $1,9502026-03-13 HIGH 7.5 CVE-2023-40583 libp2p is a networking stack and library modularized out of The IPFS Project, and bundled separately for other tools to use. In go-libp2p, by using s… Libp2p 0.27.4+ Fix from $1,9502023-08-25 HIGH 7.5 CVE-2023-25568 Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In versions 0.4.0 and 0.5.0, if an attacker is a… Boxo Patch available Fix from $1,9502023-05-10 HIGH 7.5 CVE-2023-23625 go-unixfs is an implementation of a unix-like filesystem on top of an ipld merkledag. Trying to read malformed HAMT sharded directories can cause pan… Go Unixfs 0.4.3+ Fix from $1,9502023-02-09 HIGH 7.5 CVE-2023-23626 go-bitfield is a simple bitfield package for the go language aiming to be more performant that the standard library. When feeding untrusted user inpu… Go Bitfield 1.1.0+ Fix from $1,9502023-02-09 HIGH 7.5 CVE-2023-23631 github.com/ipfs/go-unixfsnode is an ADL IPLD prime node that wraps go-codec-dagpb's implementation of protobuf to enable pathing. In versions priot t… Go Unixfsnode 1.5.2+ Fix from $1,9502023-02-09 HIGH 7.5 CVE-2023-22460 go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for C… Go Ipld Prime 0.19.0+ Fix from $1,9502023-01-04 HIGH 7.5 CVE-2022-2584 The dag-pb codec can panic when decoding invalid blocks. Go Codec Dagpb 1.3.1+ Fix from $1,9502022-12-27 MEDIUM 5.3 CVE-2022-47547 GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it continuo… Gossipsub No fix yet Fix from $1,6002022-12-19 HIGH 7.5 CVE-2022-23495 go-merkledag implements the 'DAGService' interface and adds two ipld node types, Protobuf and Raw for the ipfs project. A `ProtoNode` may be modified… Go Merkledag 0.8.1+ Fix from $1,9502022-12-08 HIGH 7.5 CVE-2022-23492 go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted res… Libp2p 0.18.0+ Fix from $1,9502022-12-08 HIGH 7.5 CVE-2022-23486 libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a vic… Libp2p 0.45.1+ Fix from $1,9502022-12-07 HIGH 7.5 CVE-2022-23487 js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted… Libp2p 0.38.0+ Fix from $1,9502022-12-07 HIGH 8.8 CVE-2020-26283 go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, contr… Go Ipfs 0.8.0+ Fix from $1,9502021-03-24 HIGH 8.1 CVE-2020-26279 go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0-rc1, i… Go Ipfs after 0.7.0 Fix from $1,9502021-03-24 HIGH 7.5 CVE-2020-35909 An issue was discovered in the multihash crate before 0.11.3 for Rust. The from_slice parsing code can panic via unsanitized data from a network serv… Multihash 0.11.3+ Fix from $1,9502020-12-31 HIGH 7.5 CVE-2020-10937 An issue was discovered in IPFS (aka go-ipfs) 0.4.23. An attacker can generate ephemeral identities (Sybils) and leverage the IPFS connection managem… Ipfs Mitigation only Fix from $1,9502020-11-02 CRITICAL 9.8 CVE-2020-12821 Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack. Gossipsub Patch available Fix from $2,3002020-07-07