CVE-2022-23487

HIGH

libp2p < 0.38.0 - Resource Exhaustion via Connection and Stream Management

Title source: llm
STIX 2.1

Description

js-libp2p is the official javascript Implementation of libp2p networking stack. Versions older than `v0.38.0` of js-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can cause the allocation of large amounts of memory, ultimately leading to the process getting killed by the host’s operating system. While a connection manager tasked with keeping the number of connections within manageable limits has been part of js-libp2p, this component was designed to handle the regular churn of peers, not a targeted resource exhaustion attack. Users are advised to update their js-libp2p dependency to `v0.38.0` or greater. There are no known workarounds for this vulnerability.

References (1)

Core 1
Core References
Mitigation, Third Party Advisory x_refsource_confirm
https://github.com/libp2p/js-libp2p/security/advisories/GHSA-f44q-634c-jvwv

Scores

CVSS v3 7.5
EPSS 0.0034
EPSS Percentile 56.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-770 CWE-400
Status published
Products (2)
npm/libp2p 0 - 0.38.0npm
protocol/libp2p < 0.38.0
Published Dec 07, 2022
Tracked Since Feb 18, 2026