Threat Advisory

Libp2p QUIC Flaw Causes Remote Panic via Certificate Expiry Race

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-61544 with a CVSS score of 8.2 is a high severity vulnerability in libp2p-quic that allows a remote attacker to cause a denial-of-service by exploiting a certificate expiry race during a QUIC handshake, resulting in a panic and potentially crashing applications exposing an affected listener. This flaw can be triggered when a malicious peer presents a valid but short-lived TLS certificate and delays the final TLS 1.3 handshake fragment until the certificate expires. The vulnerability is remotely reachable and affects versions of libp2p-quic prior to 0.13.1, which can be crashed by a network peer that performs a valid-looking QUIC/TLS handshake with attacker-controlled timing. No malformed packets are required for exploitation, making this a significant business risk as it can impact any application exposing an affected libp2p-quic listener.

RECOMMENDATION:

We recommend you to update libp2p-quic to version 0.13.1.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-61544 with a CVSS score of 8.2 is a high severity vulnerability in libp2p-quic that allows a remote attacker to cause a denial-of-service by exploiting a certificate expiry race during a QUIC handshake, resulting in a panic and potentially crashing applications exposing an affected listener. This flaw can be triggered when a malicious peer presents a valid but short-lived TLS certificate and delays the final TLS 1.3 handshake fragment until the certificate expires. The vulnerability is remotely reachable and affects versions of libp2p-quic prior to 0.13.1, which can be crashed by a network peer that performs a valid-looking QUIC/TLS handshake with attacker-controlled timing. No malformed packets are required for exploitation, making this a significant business risk as it can impact any application exposing an affected libp2p-quic listener.

RECOMMENDATION:

We recommend you to update libp2p-quic to version 0.13.1.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu