← back
CVE-2026-35457highCWE-770

libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.2epss 0.3%
exploitation probability
0.3%top 79% of all CVEs
observed exploitation
nono source reports it
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can repeatedly issue DISCOVER requests and force unbounded memory growth. This vulnerability is fixed in 0.17.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Affected products
libp2p · rust-libp2p