libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an unauthenticated single peer to exhaust the Node.js heap of any gossipsub node with default options. This issue has been patched in version 15.0.23.
References
Configurations
No configuration.
History
11 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/libp2p/js-libp2p/security/advisories/GHSA-4f8r-922h-2vgv - |
10 Jun 2026, 22:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-10 22:17
Updated : 2026-06-11 16:16
NVD link : CVE-2026-46679
Mitre link : CVE-2026-46679
CVE.ORG link : CVE-2026-46679
JSON object : View
Products Affected
No product.
