libp2p js-libp2p

3 known vulnerabilities in libp2p js-libp2p, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-86040 CVSS 7.5 high libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthenticated RPC…
  • CVE-2026-86039 CVSS 8.2 high libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in…
  • CVE-2026-86038 CVSS 7.5 high libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default…