CVE-2026-61544 with a CVSS score of 8.2 is a high severity vulnerability in libp2p-quic that allows a remote attacker to cause a denial-of-service by exploiting a certificate expiry race during a QUIC handshake, resulting in a panic and potentially crashing applications exposing an affected listener. This flaw can be triggered when a malicious peer presents a valid but short-lived TLS certificate and delays the final TLS 1.3 handshake fragment until the certificate expires. The vulnerability is remotely reachable and affects versions of libp2p-quic prior to 0.13.1, which can be crashed by a network peer that performs a valid-looking QUIC/TLS handshake with attacker-controlled timing. No malformed packets are required for exploitation, making this a significant business risk as it can impact any application exposing an affected libp2p-quic listener.
We recommend you to update libp2p-quic to version 0.13.1.[/subscribe_to_unlock_form]
CVE-2026-61544 with a CVSS score of 8.2 is a high severity vulnerability in libp2p-quic that allows a remote attacker to cause a denial-of-service by exploiting a certificate expiry race during a QUIC handshake, resulting in a panic and potentially crashing applications exposing an affected listener. This flaw can be triggered when a malicious peer presents a valid but short-lived TLS certificate and delays the final TLS 1.3 handshake fragment until the certificate expires. The vulnerability is remotely reachable and affects versions of libp2p-quic prior to 0.13.1, which can be crashed by a network peer that performs a valid-looking QUIC/TLS handshake with attacker-controlled timing. No malformed packets are required for exploitation, making this a significant business risk as it can impact any application exposing an affected libp2p-quic listener.
We recommend you to update libp2p-quic to version 0.13.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]