<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T11:37:52.080333+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-233355</id>
    <title>EUVD-2026-233355</title>
    <updated>2026-10-07T11:37:52.155925+00:00</updated>
    <content>EUVD-2026-233355</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-233355"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23492</id>
    <title>fkie_cve-2022-23492</title>
    <updated>2026-10-07T11:37:52.155963+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can cause the allocation of large amounts of memory, ultimately leading to the process getting killed by the host’s operating system. While a connection manager tasked with keeping the number of connections within manageable limits has been part of go-libp2p, this component was designed to handle the regular churn of peers, not a targeted resource exhaustion attack. Users are advised to upgrade their version of go-libp2p to version `0.18.1` or newer. Users unable to upgrade may consult the denial of service (dos) mitigation page for more information on how to incorporate mitigation strategies, monitor your application, and respond to attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-23492"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j7qp-mfxf-8xjw</id>
    <title>GHSA-j7qp-mfxf-8xjw — libp2p DoS vulnerability from lack of resource management</title>
    <updated>2026-10-07T11:37:52.156005+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/libp2p/go-libp2p</p>
<p>### Impact
Versions older than `v0.18.0` of go-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can cause the allocation of large amounts of memory, ultimately leading to the process getting killed by the host’s operating system. While a connection manager tasked with keeping the number of connections within manageable limits has been part of go-libp2p, this component was designed to handle the regular churn of peers, not a targeted resource exhaustion attack.</p>
<p>In the original version of the attack, the malicious node would continue opening new streams on a stream multiplexer that doesn’t provide sufficient back pressure (yamux or mplex). It is easy to defend against this one attack, but there are countless variations of this attack:
* Opening streams and causing a non-trivial memory allocation (e.g., for multistream or protobuf parsing)
* Creating a lot of sybil nodes and opening new connections across nodes</p>
<p>### Patches (What to do as a go-libp2p consumer:)
1. Update your go-libp2p dependency to go-libp2p v0.18.0 or greater (current version as of publish date is [v0.24.0](https://github.com/libp2p/go-libp2p/releases/tag/v0.24.0).)
    - Note: **It's recommend that you update to `v0.21.0` onwards** as you’ll get some useful functionality that will help in production environments like better metrics around resource usage, Grafana dashboards around resource usage, allow li…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j7qp-mfxf-8xjw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-23492</id>
    <title>gsd-2022-23492</title>
    <updated>2026-10-07T11:37:52.156064+00:00</updated>
    <content>gsd-2022-23492</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-23492"/>
  </entry>
</feed>
