Denial of Service Vulnerability in libp2p-rendezvous by Protocol Labs
CVE-2026-89146

8.7HIGH

Key Information:

Vendor

Libp2p

Vendor
CVE Published:
11 September 2026

What is CVE-2026-89146?

The libp2p-rendezvous product, up to version 0.17.1, is vulnerable due to insufficient validation of registration Time-to-Live (TTL) values in response to discovery requests. This oversight can allow a malicious rendezvous server to send a specially crafted discovery response featuring an unbounded TTL value. When client nodes process this data, it can lead to a panic in the node's process, causing a denial of service. This vulnerability highlights the critical importance of proper TTL handling in distributed networking applications.

Affected Version(s)

libp2p-rendezvous 0 <= 0.17.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ali Firas
.