Skip to content
Noroxi

protocol records

24 published records for vendor protocol.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
91.7%
Median publish → KEV
No record has entered KEV

All records

24 records
  • Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.

    CriticalCVSS 9.8No exploitEPSS 2%

    protocol · gossipsubJul 7, 2020

  • Control character injection in console output

    HighCVSS 8.8No exploitEPSS 2%

    protocol · go-ipfsMar 24, 2021

  • Yamux remote Panic via malformed WindowUpdate credit

    HighCVSS 8.7No exploitEPSS 1%

    protocol · yamuxMar 13, 2026

  • Yamux remote Panic via malformed Data frame with SYN set and len = 262145

    HighCVSS 8.7No exploitEPSS 1%

    protocol · yamuxMar 16, 2026

  • libp2p-rust: Gossipsub PRUNE.backoff Duration Overflow

    HighCVSS 8.7No exploitEPSS 1%

    protocol · libp2p-gossipsubMar 20, 2026

  • go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem.

    HighCVSS 8.1No exploitEPSS 2%

    protocol · go-ipfsMar 24, 2021

  • libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow

    HighCVSS 8.2No exploitEPSS 1%

    protocol · libp2p-gossipsubMar 31, 2026

  • libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion

    HighCVSS 8.2No exploitEPSS 0%

    protocol · libp2pApr 7, 2026

  • An issue was discovered in the multihash crate before 0.11.3 for Rust.

    HighCVSS 7.5No exploitEPSS 1%

    protocol · multihashDec 31, 2020

  • ProtoNode may be modified such that common method calls may panic in ipfs/go-merkledag

    HighCVSS 7.5No exploitEPSS 1%

    protocol · go-merkledagDec 8, 2022

  • An issue was discovered in IPFS (aka go-ipfs) 0.4.23.

    HighCVSS 7.5No exploitEPSS 1%

    protocol · ipfsNov 2, 2020

  • go-ipld-prime json codec may panic if asked to encode bytes

    HighCVSS 7.5No exploitEPSS 1%

    protocol · go-ipld-primeJan 4, 2023

  • go-libp2p denial of service vulnerability from lack of resource management

    HighCVSS 7.5No exploitEPSS 1%

    protocol · libp2pDec 7, 2022

  • libp2p nodes vulnerable to OOM attack

    HighCVSS 7.5No exploitEPSS 1%

    protocol · libp2pAug 25, 2023

  • Denial of service when feeding malformed size arguments in go-bitfield

    HighCVSS 7.5No exploitEPSS 1%

    protocol · go-bitfieldFeb 9, 2023

  • HAMT Decoding Panics in github.com/ipfs/go-unixfsnode

    HighCVSS 7.5No exploitEPSS 1%

    protocol · go-unixfsnodeFeb 9, 2023

  • Boxo bitswap/server: DOS unbounded persistent memory leak

    HighCVSS 7.5No exploitEPSS 1%

    protocol · boxoMay 10, 2023

  • CVE-2022-2584
    30Monitor

    Panic when decoding invalid blocks in github.com/ipld/go-codec-dagpb

    HighCVSS 7.5No exploitEPSS 1%

    protocol · go-codec-dagpbDec 27, 2022

  • libp2p denial of service vulnerability from lack of resource management

    HighCVSS 7.5No exploitEPSS 1%

    protocol · libp2pDec 7, 2022

  • libp2p-rust denial of service vulnerability from lack of resource management

    HighCVSS 7.5No exploitEPSS 1%

    protocol · libp2pDec 7, 2022

  • Denial of service in HAMT Decoding in go-unixfs

    HighCVSS 7.5No exploitEPSS 1%

    protocol · go-unixfsFeb 9, 2023

  • libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers

    HighCVSS 7.5No exploitEPSS 0%

    protocol · libp2pApr 7, 2026

  • go-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headers

    MediumCVSS 6.2No exploitEPSS 0%

    protocol · go-ipld-primeApr 7, 2026

  • GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it

    MediumCVSS 5.3No exploitEPSS 1%

    protocol · gossipsubDec 19, 2022