<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:libp2p:libp2p-Rendezvous:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3alibp2plibp2p-rendezvous/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 11 Sep 2026 13:13:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3alibp2plibp2p-rendezvous/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service Vulnerability in libp2p-rendezvous</title><link>https://feed.craftedsignal.io/briefs/2026-09-libp2p-dos/</link><pubDate>Fri, 11 Sep 2026 13:13:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-libp2p-dos/</guid><description>A vulnerability in libp2p-rendezvous through version 0.17.1 allows malicious rendezvous servers to crash client nodes by providing an unbounded registration TTL value.</description><content:encoded><![CDATA[<p>The libp2p-rendezvous library, in versions up to and including 0.17.1, contains a vulnerability involving the improper validation of Time-to-Live (TTL) values received in discovery responses. An attacker operating a malicious rendezvous server can send a specially crafted discovery response containing an arbitrarily large or malformed TTL value. When the client node receives this response and attempts to perform arithmetic operations for its internal expiry timers, the input triggers an integer overflow. This overflow causes the application process to panic and results in an immediate crash. As a result, the vulnerability acts as a remote denial-of-service vector against any libp2p node relying on the affected rendezvous library for peer discovery. Defenders should identify services utilizing libp2p-rendezvous and update to the patched version once available.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the remote termination of the libp2p-rendezvous client process, leading to service disruption. This vulnerability impacts any system utilizing this library for P2P networking, potentially affecting decentralized applications, distributed data systems, or custom P2P-based network services.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching of all systems utilizing libp2p-rendezvous to a version beyond 0.17.1 as soon as an update is released by the maintainers. Monitor system logs for frequent process crashes or unexpected panics in applications leveraging this specific library. Conduct an inventory check of software dependencies to identify the inclusion of libp2p-rendezvous versions 0.17.1 or lower.</p>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>libp2p</category></item></channel></rss>