Denial of Service Vulnerability in libp2p-rendezvous by Protocol Labs
CVE-2026-89146
8.7HIGH
What is CVE-2026-89146?
The libp2p-rendezvous product, up to version 0.17.1, is vulnerable due to insufficient validation of registration Time-to-Live (TTL) values in response to discovery requests. This oversight can allow a malicious rendezvous server to send a specially crafted discovery response featuring an unbounded TTL value. When client nodes process this data, it can lead to a panic in the node's process, causing a denial of service. This vulnerability highlights the critical importance of proper TTL handling in distributed networking applications.
Affected Version(s)
libp2p-rendezvous 0 <= 0.17.1
