Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Go Ipld Prime MEDIUM 6.2
CVE-2026-35480

go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for C…

Fix: 0.22.0+
Fix from $1,600 2026-04-07
Libp2p HIGH 8.2
CVE-2026-35457

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination coo…

Fix: 0.17.1+
Fix from $1,950 2026-04-07
Libp2p HIGH 7.5
CVE-2026-35405

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on ho…

Fix: 0.17.1+
Fix from $1,950 2026-04-07
Libp2p Gossipsub MEDIUM 5.9
CVE-2026-34219

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implement…

Fix: 0.49.4+
Fix from $1,600 2026-03-31
Libp2p Gossipsub HIGH 7.5
CVE-2026-33040

libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.49.3, the Gossipsub implementation ac…

Fix: 0.49.3+
Fix from $1,950 2026-03-20
Yamux HIGH 7.5
CVE-2026-32314

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementation of Yamux can panic when pr…

Fix: 0.13.10+
Fix from $1,950 2026-03-16
Yamux HIGH 7.5
CVE-2026-31814

Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a specially crafted WindowUpdate can c…

Fix: 0.13.9+
Fix from $1,950 2026-03-13
Libp2p HIGH 7.5
CVE-2023-40583

libp2p is a networking stack and library modularized out of The IPFS Project, and bundled separately for other tools to use. In go-libp2p, by using s…

Fix: 0.27.4+
Fix from $1,950 2023-08-25
Boxo HIGH 7.5
CVE-2023-25568

Boxo, formerly known as go-libipfs, is a library for building IPFS applications and implementations. In versions 0.4.0 and 0.5.0, if an attacker is a…

Patch available
Fix from $1,950 2023-05-10
Go Unixfs HIGH 7.5
CVE-2023-23625

go-unixfs is an implementation of a unix-like filesystem on top of an ipld merkledag. Trying to read malformed HAMT sharded directories can cause pan…

Fix: 0.4.3+
Fix from $1,950 2023-02-09
Go Bitfield HIGH 7.5
CVE-2023-23626

go-bitfield is a simple bitfield package for the go language aiming to be more performant that the standard library. When feeding untrusted user inpu…

Fix: 1.1.0+
Fix from $1,950 2023-02-09
Go Unixfsnode HIGH 7.5
CVE-2023-23631

github.com/ipfs/go-unixfsnode is an ADL IPLD prime node that wraps go-codec-dagpb's implementation of protobuf to enable pathing. In versions priot t…

Fix: 1.5.2+
Fix from $1,950 2023-02-09
Go Ipld Prime HIGH 7.5
CVE-2023-22460

go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for C…

Fix: 0.19.0+
Fix from $1,950 2023-01-04
Go Codec Dagpb HIGH 7.5
CVE-2022-2584

The dag-pb codec can panic when decoding invalid blocks.

Fix: 1.3.1+
Fix from $1,950 2022-12-27
Gossipsub MEDIUM 5.3
CVE-2022-47547

GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it continuo…

No fix yet
Fix from $1,600 2022-12-19
Go Merkledag HIGH 7.5
CVE-2022-23495

go-merkledag implements the 'DAGService' interface and adds two ipld node types, Protobuf and Raw for the ipfs project. A `ProtoNode` may be modified…

Fix: 0.8.1+
Fix from $1,950 2022-12-08
Libp2p HIGH 7.5
CVE-2022-23492

go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted res…

Fix: 0.18.0+
Fix from $1,950 2022-12-08
Libp2p HIGH 7.5
CVE-2022-23486

libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.45.1 an attacker node can cause a vic…

Fix: 0.45.1+
Fix from $1,950 2022-12-07
Libp2p HIGH 7.5
CVE-2022-23487

js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted…

Fix: 0.38.0+
Fix from $1,950 2022-12-07
Go Ipfs HIGH 8.8
CVE-2020-26283

go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, contr…

Fix: 0.8.0+
Fix from $1,950 2021-03-24
Go Ipfs HIGH 8.1
CVE-2020-26279

go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0-rc1, i…

Fix: after 0.7.0
Fix from $1,950 2021-03-24
Multihash HIGH 7.5
CVE-2020-35909

An issue was discovered in the multihash crate before 0.11.3 for Rust. The from_slice parsing code can panic via unsanitized data from a network serv…

Fix: 0.11.3+
Fix from $1,950 2020-12-31
Ipfs HIGH 7.5
CVE-2020-10937

An issue was discovered in IPFS (aka go-ipfs) 0.4.23. An attacker can generate ephemeral identities (Sybils) and leverage the IPFS connection managem…

Mitigation only
Fix from $1,950 2020-11-02
Gossipsub CRITICAL 9.8
CVE-2020-12821

Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.

Patch available
Fix from $2,300 2020-07-07