HIGHGo →
libp2p nodes vulnerable to attack using large RSA keys
libp2p nodes vulnerable to attack using large RSA keys
Affected packages
- github.com/libp2p/go-libp2p
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/libp2p/go-libp2p/security/advisories/GHSA-876p-8259-xjgg
- https://nvd.nist.gov/vuln/detail/CVE-2023-39533
- https://github.com/golang/go/issues/61460
- https://github.com/libp2p/go-libp2p/pull/2454
- https://github.com/quic-go/quic-go/pull/4012
- https://github.com/golang/go/commit/2350afd2e8ab054390e284c95d5b089c142db017
- https://github.com/libp2p/go-libp2p/commit/0cce607219f3710addc7e18672cffd1f1d912fbb
- https://github.com/libp2p/go-libp2p/commit/445be526aea4ee0b1fa5388aa65d32b2816d3a00
- https://github.com/libp2p/go-libp2p/commit/e30fcf7dfd4715ed89a5e68d7a4f774d3b9aa92d
- https://github.com/libp2p/go-libp2p
- https://go.dev/issue/61460
- https://nrdax.com/techniques/NRDAX-T0205-pre-handshake-crypto-cpu-burn
Structured record: https://osv.dev/vulnerability/GHSA-876p-8259-xjgg
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta