{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3alibp2plibp2p-quic/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:libp2p:libp2p-quic:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-61544"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["libp2p-quic (\u003c 0.13.1)"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","libp2p","rust"],"_cs_type":"advisory","_cs_vendors":["libp2p"],"content_html":"\u003cp\u003eThe \u003ccode\u003elibp2p-quic\u003c/code\u003e crate is susceptible to a remote unauthenticated denial-of-service vulnerability (CVE-2026-61544) resulting from improper error handling during the QUIC/TLS handshake process. The vulnerability stems from a race condition where the library performs two distinct certificate validations. The first validation succeeds when the connection is established; however, a second, post-handshake validation is performed during the upgrade path. If a malicious peer presents a valid, short-lived certificate and intentionally delays sending the final TLS 1.3 handshake fragment until after the certificate's validity period has elapsed, the second validation check fails. Because the library incorrectly assumes this second parse cannot fail, it triggers an unhandled \u003ccode\u003eexpect()\u003c/code\u003e call, leading to a process panic and application crash. This affects any application utilizing \u003ccode\u003elibp2p-quic\u003c/code\u003e versions prior to 0.13.1.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker initiates a standard QUIC connection to a listener running an affected version of \u003ccode\u003elibp2p-quic\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker provides a legitimate, short-lived libp2p TLS certificate.\u003c/li\u003e\n\u003cli\u003eThe target's \u003ccode\u003elibp2p-tls\u003c/code\u003e component successfully parses and validates the certificate during the initial handshake.\u003c/li\u003e\n\u003cli\u003eThe Quinn protocol stack reports the handshake completion to the application.\u003c/li\u003e\n\u003cli\u003eAttacker purposefully withholds the final client handshake fragment packet.\u003c/li\u003e\n\u003cli\u003eAttacker waits until the certificate has expired while remaining within the application's QUIC handshake timeout threshold.\u003c/li\u003e\n\u003cli\u003eAttacker transmits the delayed final handshake fragment to the target.\u003c/li\u003e\n\u003cli\u003eThe target performs the post-handshake certificate re-parse, encounters a failure due to the expired certificate, and triggers an unhandled panic.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in an immediate, remote unauthenticated denial-of-service. Because the vulnerability triggers a process-level panic, it causes an abrupt crash of the host application, potentially impacting all active connections and services handled by that instance. The attack requires no malformed packets, making it difficult to detect via traditional signature-based protocol inspection.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003elibp2p-quic\u003c/code\u003e to version 0.13.1 or later to resolve the panic condition in the connection upgrade path.\u003c/li\u003e\n\u003cli\u003eAudit network ingress traffic for an unusual frequency of long-duration QUIC handshakes that fail shortly after initiation.\u003c/li\u003e\n\u003cli\u003eImplement process monitoring to detect service restarts or crashes associated with \u003ccode\u003elibp2p-quic\u003c/code\u003e dependencies.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T01:05:35Z","date_published":"2026-09-16T01:05:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-libp2p-quic-panic/","summary":"A malicious peer can trigger an application crash in libp2p-quic (\u003c 0.13.1) by initiating a QUIC handshake and delaying the final TLS fragment until the peer certificate expires, causing an unhandled panic.","title":"Remote Denial of Service in libp2p-quic via Certificate Expiry Race","url":"https://feed.craftedsignal.io/briefs/2026-09-libp2p-quic-panic/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:libp2p:libp2p-Quic:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}