libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an unauthenticated single peer to exhaust the Node.js heap of any gossipsub node with default options. This issue has been patched in version 15.0.23.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4f8r-922h-2vgv | js-libp2p: Memory DoS via subscription flood of unique topics |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 10 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an unauthenticated single peer to exhaust the Node.js heap of any gossipsub node with default options. This issue has been patched in version 15.0.23. | |
| Title | libp2p: Memory DoS via subscription flood of unique topics | |
| Weaknesses | CWE-20 CWE-400 CWE-401 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-10T21:08:52.464Z
Reserved: 2026-05-15T21:46:51.547Z
Link: CVE-2026-46679
No data.
Status : Received
Published: 2026-06-10T22:17:00.300
Modified: 2026-06-10T22:17:00.300
Link: CVE-2026-46679
No data.
OpenCVE Enrichment
No data.
Github GHSA