Arithmetic Overflow Vulnerability in Yamux Stream Multiplexer by libp2p
CVE-2026-31814

8.7HIGH

Key Information:

Vendor

Libp2p

Vendor
CVE Published:
13 March 2026

What is CVE-2026-31814?

The Yamux stream multiplexer, developed by libp2p, is susceptible to an arithmetic overflow due to a specially crafted WindowUpdate packet. This issue affects versions 0.13.0 through 0.13.8, allowing an attacker to exploit the vulnerability remotely over a standard network connection without requiring authentication. The vulnerability can lead to a panic in the connection state machine, significantly affecting the application's stability. Users should upgrade to version 0.13.9 or later to mitigate this risk. For detailed information, consult the advisory at GitHub Security Advisory.

Affected Version(s)

rust-yamux >= 0.13.0, < 0.13.9

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.