Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c3gv-825q-fvmp | libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 17 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses the default StrictSign policy in packages/gossipsub/src/utils/buildRawMessage.ts, where validateToRawMessage verifies a signature with attacker-controlled msg.key but skips binding that key to msg.from when the claimed author is an RSA peer ID that does not inline a public key. An unauthenticated attacker can place a victim RSA peer ID in msg.from, sign the message with the attacker's private key, and supply the attacker's public key in msg.key, causing the message to be accepted and propagated as authored by the victim. Applications that trust message.from for validators, authorization, accounting, moderation, reputation, or audit logging can process attacker-controlled data under false origin attribution. The issue is fixed in version 16.0.5. | |
| Title | libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID | |
| Weaknesses | CWE-345 CWE-347 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-17T17:24:35.905Z
Reserved: 2026-09-04T19:29:21.057Z
Link: CVE-2026-86038
Updated: 2026-09-17T17:24:29.895Z
Status : Received
Published: 2026-09-17T16:18:16.927
Modified: 2026-09-17T18:17:12.203
Link: CVE-2026-86038
No data.
OpenCVE Enrichment
No data.
Github GHSA