CVE-2026-89146
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-190
Desbordamiento o ajuste de enteros
Fecha de publicación:
11/09/2026
Última modificación:
23/09/2026
Descripción
*** Pendiente de traducción *** libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process to panic when computing the expiry timer.
Impacto
Puntuación base 4.0
8.70
Gravedad 4.0
ALTA
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA
Referencias a soluciones, herramientas e información
- https://docs.rs/crate/libp2p-rendezvous/0.17.1/source/src/client.rs
- https://gist.github.com/thesmartshadow/25ef03f7ebbd12118a9d27695c885989
- https://github.com/libp2p/rust-libp2p
- https://www.vulncheck.com/advisories/libp2p-rendezvous-through-0.17.1-denial-of-service-via-unbounded-registration-ttl-in-discovery-responses
- https://gist.github.com/thesmartshadow/25ef03f7ebbd12118a9d27695c885989


