Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer can repeatedly send valid RESERVE requests for the same reservation, causing unbounded listener and closure growth in @libp2p/circuit-relay-v2 relay servers and leading to denial of service. This issue is fixed in version 4.2.9. | |
| Title | libp2p: Circuit relay v2 server reservation refresh leaks abort listeners and allows remote resource exhaustion | |
| Weaknesses | CWE-400 CWE-772 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-24T21:06:39.909Z
Reserved: 2026-08-20T19:36:13.806Z
Link: CVE-2026-77384
No data.
Status : Received
Published: 2026-08-24T22:17:19.650
Modified: 2026-08-24T22:17:19.650
Link: CVE-2026-77384
No data.
OpenCVE Enrichment
No data.