protocol records
24 published records for vendor protocol.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 91.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption7
- CWE-190 Integer Overflow or Wraparound3
- CWE-770 Allocation of Resources Without Limits or Throttling3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-281 Improper Preservation of Permissions1
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-12821No exploit | Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.protocol · gossipsub | Critical9.8 | — | 1.9% | Jul 7, 2020 |
35Monitor | CVE-2020-26283No exploit | Control character injection in console outputprotocol · go-ipfs · CWE-116 | High8.8 | — | 1.5% | Mar 24, 2021 |
34Monitor | CVE-2026-31814No exploit | Yamux remote Panic via malformed WindowUpdate creditprotocol · yamux · CWE-190 | High8.7 | — | 0.6% | Mar 13, 2026 |
34Monitor | CVE-2026-32314No exploit | Yamux remote Panic via malformed Data frame with SYN set and len = 262145protocol · yamux · CWE-248 | High8.7 | — | 0.6% | Mar 16, 2026 |
34Monitor | CVE-2026-33040No exploit | libp2p-rust: Gossipsub PRUNE.backoff Duration Overflowprotocol · libp2p-gossipsub · CWE-190 | High8.7 | — | 0.5% | Mar 20, 2026 |
33Monitor | CVE-2020-26279No exploit | go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem.protocol · go-ipfs · CWE-22 | High8.1 | — | 1.7% | Mar 24, 2021 |
32Monitor | CVE-2026-34219No exploit | libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflowprotocol · libp2p-gossipsub · CWE-190 | High8.2 | — | 0.5% | Mar 31, 2026 |
32Monitor | CVE-2026-35457No exploit | libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustionprotocol · libp2p · CWE-770 | High8.2 | — | 0.4% | Apr 7, 2026 |
30Monitor | CVE-2020-35909No exploit | An issue was discovered in the multihash crate before 0.11.3 for Rust.protocol · multihash | High7.5 | — | 1.4% | Dec 31, 2020 |
30Monitor | CVE-2022-23495No exploit | ProtoNode may be modified such that common method calls may panic in ipfs/go-merkledagprotocol · go-merkledag · CWE-755 | High7.5 | — | 1.3% | Dec 8, 2022 |
30Monitor | CVE-2020-10937No exploit | An issue was discovered in IPFS (aka go-ipfs) 0.4.23.protocol · ipfs | High7.5 | — | 1.2% | Nov 2, 2020 |
30Monitor | CVE-2023-22460No exploit | go-ipld-prime json codec may panic if asked to encode bytesprotocol · go-ipld-prime · CWE-20 | High7.5 | — | 1.1% | Jan 4, 2023 |
30Monitor | CVE-2022-23492No exploit | go-libp2p denial of service vulnerability from lack of resource managementprotocol · libp2p · CWE-400 | High7.5 | — | 1.0% | Dec 7, 2022 |
30Monitor | CVE-2023-40583No exploit | libp2p nodes vulnerable to OOM attackprotocol · libp2p · CWE-400 | High7.5 | — | 1.0% | Aug 25, 2023 |
30Monitor | CVE-2023-23626No exploit | Denial of service when feeding malformed size arguments in go-bitfieldprotocol · go-bitfield · CWE-754 | High7.5 | — | 0.9% | Feb 9, 2023 |
30Monitor | CVE-2023-23631No exploit | HAMT Decoding Panics in github.com/ipfs/go-unixfsnodeprotocol · go-unixfsnode · CWE-400 | High7.5 | — | 0.9% | Feb 9, 2023 |
30Monitor | CVE-2023-25568No exploit | Boxo bitswap/server: DOS unbounded persistent memory leakprotocol · boxo · CWE-400 | High7.5 | — | 0.9% | May 10, 2023 |
30Monitor | CVE-2022-2584No exploit | Panic when decoding invalid blocks in github.com/ipld/go-codec-dagpbprotocol · go-codec-dagpb · CWE-119 | High7.5 | — | 0.7% | Dec 27, 2022 |
30Monitor | CVE-2022-23487No exploit | libp2p denial of service vulnerability from lack of resource managementprotocol · libp2p · CWE-400 | High7.5 | — | 0.7% | Dec 7, 2022 |
30Monitor | CVE-2022-23486No exploit | libp2p-rust denial of service vulnerability from lack of resource managementprotocol · libp2p · CWE-400 | High7.5 | — | 0.7% | Dec 7, 2022 |
30Monitor | CVE-2023-23625No exploit | Denial of service in HAMT Decoding in go-unixfsprotocol · go-unixfs · CWE-400 | High7.5 | — | 0.7% | Feb 9, 2023 |
30Monitor | CVE-2026-35405No exploit | libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous serversprotocol · libp2p · CWE-770 | High7.5 | — | 0.5% | Apr 7, 2026 |
24Monitor | CVE-2026-35480No exploit | go-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headersprotocol · go-ipld-prime · CWE-770 | Medium6.2 | — | 0.2% | Apr 7, 2026 |
21Monitor | CVE-2022-47547No exploit | GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though itprotocol · gossipsub · CWE-281 | Medium5.3 | — | 0.5% | Dec 19, 2022 |
- CVE-2020-1282140Plan
Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.
CriticalCVSS 9.8No exploitEPSS 2%protocol · gossipsubJul 7, 2020
- CVE-2020-2628335Monitor
Control character injection in console output
HighCVSS 8.8No exploitEPSS 2%protocol · go-ipfsMar 24, 2021
- CVE-2026-3181434Monitor
Yamux remote Panic via malformed WindowUpdate credit
HighCVSS 8.7No exploitEPSS 1%protocol · yamuxMar 13, 2026
- CVE-2026-3231434Monitor
Yamux remote Panic via malformed Data frame with SYN set and len = 262145
HighCVSS 8.7No exploitEPSS 1%protocol · yamuxMar 16, 2026
- CVE-2026-3304034Monitor
libp2p-rust: Gossipsub PRUNE.backoff Duration Overflow
HighCVSS 8.7No exploitEPSS 1%protocol · libp2p-gossipsubMar 20, 2026
- CVE-2020-2627933Monitor
go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem.
HighCVSS 8.1No exploitEPSS 2%protocol · go-ipfsMar 24, 2021
- CVE-2026-3421932Monitor
libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow
HighCVSS 8.2No exploitEPSS 1%protocol · libp2p-gossipsubMar 31, 2026
- CVE-2026-3545732Monitor
libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion
HighCVSS 8.2No exploitEPSS 0%protocol · libp2pApr 7, 2026
- CVE-2020-3590930Monitor
An issue was discovered in the multihash crate before 0.11.3 for Rust.
HighCVSS 7.5No exploitEPSS 1%protocol · multihashDec 31, 2020
- CVE-2022-2349530Monitor
ProtoNode may be modified such that common method calls may panic in ipfs/go-merkledag
HighCVSS 7.5No exploitEPSS 1%protocol · go-merkledagDec 8, 2022
- CVE-2020-1093730Monitor
An issue was discovered in IPFS (aka go-ipfs) 0.4.23.
HighCVSS 7.5No exploitEPSS 1%protocol · ipfsNov 2, 2020
- CVE-2023-2246030Monitor
go-ipld-prime json codec may panic if asked to encode bytes
HighCVSS 7.5No exploitEPSS 1%protocol · go-ipld-primeJan 4, 2023
- CVE-2022-2349230Monitor
go-libp2p denial of service vulnerability from lack of resource management
HighCVSS 7.5No exploitEPSS 1%protocol · libp2pDec 7, 2022
- CVE-2023-4058330Monitor
libp2p nodes vulnerable to OOM attack
HighCVSS 7.5No exploitEPSS 1%protocol · libp2pAug 25, 2023
- CVE-2023-2362630Monitor
Denial of service when feeding malformed size arguments in go-bitfield
HighCVSS 7.5No exploitEPSS 1%protocol · go-bitfieldFeb 9, 2023
- CVE-2023-2363130Monitor
HAMT Decoding Panics in github.com/ipfs/go-unixfsnode
HighCVSS 7.5No exploitEPSS 1%protocol · go-unixfsnodeFeb 9, 2023
- CVE-2023-2556830Monitor
Boxo bitswap/server: DOS unbounded persistent memory leak
HighCVSS 7.5No exploitEPSS 1%protocol · boxoMay 10, 2023
- CVE-2022-258430Monitor
Panic when decoding invalid blocks in github.com/ipld/go-codec-dagpb
HighCVSS 7.5No exploitEPSS 1%protocol · go-codec-dagpbDec 27, 2022
- CVE-2022-2348730Monitor
libp2p denial of service vulnerability from lack of resource management
HighCVSS 7.5No exploitEPSS 1%protocol · libp2pDec 7, 2022
- CVE-2022-2348630Monitor
libp2p-rust denial of service vulnerability from lack of resource management
HighCVSS 7.5No exploitEPSS 1%protocol · libp2pDec 7, 2022
- CVE-2023-2362530Monitor
Denial of service in HAMT Decoding in go-unixfs
HighCVSS 7.5No exploitEPSS 1%protocol · go-unixfsFeb 9, 2023
- CVE-2026-3540530Monitor
libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers
HighCVSS 7.5No exploitEPSS 0%protocol · libp2pApr 7, 2026
- CVE-2026-3548024Monitor
go-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headers
MediumCVSS 6.2No exploitEPSS 0%protocol · go-ipld-primeApr 7, 2026
- CVE-2022-4754721Monitor
GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it
MediumCVSS 5.3No exploitEPSS 1%protocol · gossipsubDec 19, 2022