CVE-2026-46679

HIGH

libp2p: Memory DoS via subscription flood of unique topics

Title source: cna
STIX 2.1

Description

libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an unauthenticated single peer to exhaust the Node.js heap of any gossipsub node with default options. This issue has been patched in version 15.0.23.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0026
EPSS Percentile 17.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-20 CWE-400 CWE-401
Status published
Products (2)
libp2p/gossipsub 0 - 15.0.23npm
libp2p/js-libp2p < 15.0.23
Published Jun 10, 2026
Tracked Since Jun 11, 2026