Vulnerabilities/

libp2p DoS vulnerability from lack of resource management

Severity:
High

Description

Versions older than v0.38.0 of js-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can cause the allocation of large amounts of memory, ultimately leading to the process getting killed by the host’s operating system.

Recommendation

Update the libp2p package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
libp2p
Anything's wrong? Let us know Last updated on July 14, 2023

This issue is available in SmartScanner Professional

See Pricing