Arithmetic Overflow Vulnerability in Yamux Stream Multiplexer by libp2p
CVE-2026-31814
8.7HIGH
What is CVE-2026-31814?
The Yamux stream multiplexer, developed by libp2p, is susceptible to an arithmetic overflow due to a specially crafted WindowUpdate packet. This issue affects versions 0.13.0 through 0.13.8, allowing an attacker to exploit the vulnerability remotely over a standard network connection without requiring authentication. The vulnerability can lead to a panic in the connection state machine, significantly affecting the application's stability. Users should upgrade to version 0.13.9 or later to mitigate this risk. For detailed information, consult the advisory at GitHub Security Advisory.
Affected Version(s)
rust-yamux >= 0.13.0, < 0.13.9
