EXECUTIVE SUMMARY:
Two high-severity vulnerabilities affect identity verification in @libp2p/gossipsub and @libp2p/peer-store components. The flaws allow attackers to forge Gossipsub messages that appear to originate from arbitrary victim RSA peer IDs and submit signed PeerRecords containing a victim's peer ID with attacker-controlled addresses, resulting in certified address poisoning and potential dial redirection or reachability disruption.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Two high-severity vulnerabilities affect identity verification in @libp2p/gossipsub and @libp2p/peer-store components. The flaws allow attackers to forge Gossipsub messages that appear to originate from arbitrary victim RSA peer IDs and submit signed PeerRecords containing a victim's peer ID with attacker-controlled addresses, resulting in certified address poisoning and potential dial redirection or reachability disruption.[emaillocker id="1283"]
CVE-2026-86038 (CVSS 7.5 — High): It is a vulnerability in @libp2p/gossipsub that allows attackers to forge messages attributed to arbitrary victim RSA peer IDs using attacker-controlled public keys and signatures.
CVE-2026-86039 (CVSS 8.2 — High): It is a vulnerability in @libp2p/peer-store that allows attackers to poison certified address records for victim peer IDs using attacker-controlled multiaddrs.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-c3gv-825q-fvmp
https://github.com/advisories/GHSA-vrf4-mx87-p53w