Threat Advisory

libp2p Vulnerabilities Enable Modified Verified Node Identifiers

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Two high-severity vulnerabilities affect identity verification in @libp2p/gossipsub and @libp2p/peer-store components. The flaws allow attackers to forge Gossipsub messages that appear to originate from arbitrary victim RSA peer IDs and submit signed PeerRecords containing a victim's peer ID with attacker-controlled addresses, resulting in certified address poisoning and potential dial redirection or reachability disruption.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Two high-severity vulnerabilities affect identity verification in @libp2p/gossipsub and @libp2p/peer-store components. The flaws allow attackers to forge Gossipsub messages that appear to originate from arbitrary victim RSA peer IDs and submit signed PeerRecords containing a victim's peer ID with attacker-controlled addresses, resulting in certified address poisoning and potential dial redirection or reachability disruption.[emaillocker id="1283"]

CVE-2026-86038 (CVSS 7.5 — High): It is a vulnerability in @libp2p/gossipsub that allows attackers to forge messages attributed to arbitrary victim RSA peer IDs using attacker-controlled public keys and signatures.

CVE-2026-86039 (CVSS 8.2 — High): It is a vulnerability in @libp2p/peer-store that allows attackers to poison certified address records for victim peer IDs using attacker-controlled multiaddrs.

 

RECOMMENDATIONS:

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-c3gv-825q-fvmp
https://github.com/advisories/GHSA-vrf4-mx87-p53w

[/emaillocker]
crossmenu