protocol kayıtları
protocol üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %91,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption7
- CWE-190 Integer Overflow or Wraparound3
- CWE-770 Allocation of Resources Without Limits or Throttling3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-281 Improper Preservation of Permissions1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-12821İstismar yok | Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.protocol · gossipsub | Kritik9,8 | — | %1,9 | 7 Tem 2020 |
35İzleyin | CVE-2020-26283İstismar yok | Control character injection in console outputprotocol · go-ipfs · CWE-116 | Yüksek8,8 | — | %1,5 | 24 Mar 2021 |
34İzleyin | CVE-2026-31814İstismar yok | Yamux remote Panic via malformed WindowUpdate creditprotocol · yamux · CWE-190 | Yüksek8,7 | — | %0,6 | 13 Mar 2026 |
34İzleyin | CVE-2026-32314İstismar yok | Yamux remote Panic via malformed Data frame with SYN set and len = 262145protocol · yamux · CWE-248 | Yüksek8,7 | — | %0,6 | 16 Mar 2026 |
34İzleyin | CVE-2026-33040İstismar yok | libp2p-rust: Gossipsub PRUNE.backoff Duration Overflowprotocol · libp2p-gossipsub · CWE-190 | Yüksek8,7 | — | %0,5 | 20 Mar 2026 |
33İzleyin | CVE-2020-26279İstismar yok | go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem.protocol · go-ipfs · CWE-22 | Yüksek8,1 | — | %1,7 | 24 Mar 2021 |
32İzleyin | CVE-2026-34219İstismar yok | libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflowprotocol · libp2p-gossipsub · CWE-190 | Yüksek8,2 | — | %0,5 | 31 Mar 2026 |
32İzleyin | CVE-2026-35457İstismar yok | libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustionprotocol · libp2p · CWE-770 | Yüksek8,2 | — | %0,4 | 7 Nis 2026 |
30İzleyin | CVE-2020-35909İstismar yok | An issue was discovered in the multihash crate before 0.11.3 for Rust.protocol · multihash | Yüksek7,5 | — | %1,4 | 31 Ara 2020 |
30İzleyin | CVE-2022-23495İstismar yok | ProtoNode may be modified such that common method calls may panic in ipfs/go-merkledagprotocol · go-merkledag · CWE-755 | Yüksek7,5 | — | %1,3 | 8 Ara 2022 |
30İzleyin | CVE-2020-10937İstismar yok | An issue was discovered in IPFS (aka go-ipfs) 0.4.23.protocol · ipfs | Yüksek7,5 | — | %1,2 | 2 Kas 2020 |
30İzleyin | CVE-2023-22460İstismar yok | go-ipld-prime json codec may panic if asked to encode bytesprotocol · go-ipld-prime · CWE-20 | Yüksek7,5 | — | %1,1 | 4 Oca 2023 |
30İzleyin | CVE-2022-23492İstismar yok | go-libp2p denial of service vulnerability from lack of resource managementprotocol · libp2p · CWE-400 | Yüksek7,5 | — | %1,0 | 7 Ara 2022 |
30İzleyin | CVE-2023-40583İstismar yok | libp2p nodes vulnerable to OOM attackprotocol · libp2p · CWE-400 | Yüksek7,5 | — | %1,0 | 25 Ağu 2023 |
30İzleyin | CVE-2023-23626İstismar yok | Denial of service when feeding malformed size arguments in go-bitfieldprotocol · go-bitfield · CWE-754 | Yüksek7,5 | — | %0,9 | 9 Şub 2023 |
30İzleyin | CVE-2023-23631İstismar yok | HAMT Decoding Panics in github.com/ipfs/go-unixfsnodeprotocol · go-unixfsnode · CWE-400 | Yüksek7,5 | — | %0,9 | 9 Şub 2023 |
30İzleyin | CVE-2023-25568İstismar yok | Boxo bitswap/server: DOS unbounded persistent memory leakprotocol · boxo · CWE-400 | Yüksek7,5 | — | %0,9 | 10 May 2023 |
30İzleyin | CVE-2022-2584İstismar yok | Panic when decoding invalid blocks in github.com/ipld/go-codec-dagpbprotocol · go-codec-dagpb · CWE-119 | Yüksek7,5 | — | %0,7 | 27 Ara 2022 |
30İzleyin | CVE-2022-23487İstismar yok | libp2p denial of service vulnerability from lack of resource managementprotocol · libp2p · CWE-400 | Yüksek7,5 | — | %0,7 | 7 Ara 2022 |
30İzleyin | CVE-2022-23486İstismar yok | libp2p-rust denial of service vulnerability from lack of resource managementprotocol · libp2p · CWE-400 | Yüksek7,5 | — | %0,7 | 7 Ara 2022 |
30İzleyin | CVE-2023-23625İstismar yok | Denial of service in HAMT Decoding in go-unixfsprotocol · go-unixfs · CWE-400 | Yüksek7,5 | — | %0,7 | 9 Şub 2023 |
30İzleyin | CVE-2026-35405İstismar yok | libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous serversprotocol · libp2p · CWE-770 | Yüksek7,5 | — | %0,5 | 7 Nis 2026 |
24İzleyin | CVE-2026-35480İstismar yok | go-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headersprotocol · go-ipld-prime · CWE-770 | Orta6,2 | — | %0,2 | 7 Nis 2026 |
21İzleyin | CVE-2022-47547İstismar yok | GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though itprotocol · gossipsub · CWE-281 | Orta5,3 | — | %0,5 | 19 Ara 2022 |
- CVE-2020-1282140Planlayın
Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.
KritikCVSS 9,8İstismar yokEPSS %2protocol · gossipsub7 Tem 2020
- CVE-2020-2628335İzleyin
Control character injection in console output
YüksekCVSS 8,8İstismar yokEPSS %2protocol · go-ipfs24 Mar 2021
- CVE-2026-3181434İzleyin
Yamux remote Panic via malformed WindowUpdate credit
YüksekCVSS 8,7İstismar yokEPSS %1protocol · yamux13 Mar 2026
- CVE-2026-3231434İzleyin
Yamux remote Panic via malformed Data frame with SYN set and len = 262145
YüksekCVSS 8,7İstismar yokEPSS %1protocol · yamux16 Mar 2026
- CVE-2026-3304034İzleyin
libp2p-rust: Gossipsub PRUNE.backoff Duration Overflow
YüksekCVSS 8,7İstismar yokEPSS %1protocol · libp2p-gossipsub20 Mar 2026
- CVE-2020-2627933İzleyin
go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem.
YüksekCVSS 8,1İstismar yokEPSS %2protocol · go-ipfs24 Mar 2021
- CVE-2026-3421932İzleyin
libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow
YüksekCVSS 8,2İstismar yokEPSS %1protocol · libp2p-gossipsub31 Mar 2026
- CVE-2026-3545732İzleyin
libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion
YüksekCVSS 8,2İstismar yokEPSS %0protocol · libp2p7 Nis 2026
- CVE-2020-3590930İzleyin
An issue was discovered in the multihash crate before 0.11.3 for Rust.
YüksekCVSS 7,5İstismar yokEPSS %1protocol · multihash31 Ara 2020
- CVE-2022-2349530İzleyin
ProtoNode may be modified such that common method calls may panic in ipfs/go-merkledag
YüksekCVSS 7,5İstismar yokEPSS %1protocol · go-merkledag8 Ara 2022
- CVE-2020-1093730İzleyin
An issue was discovered in IPFS (aka go-ipfs) 0.4.23.
YüksekCVSS 7,5İstismar yokEPSS %1protocol · ipfs2 Kas 2020
- CVE-2023-2246030İzleyin
go-ipld-prime json codec may panic if asked to encode bytes
YüksekCVSS 7,5İstismar yokEPSS %1protocol · go-ipld-prime4 Oca 2023
- CVE-2022-2349230İzleyin
go-libp2p denial of service vulnerability from lack of resource management
YüksekCVSS 7,5İstismar yokEPSS %1protocol · libp2p7 Ara 2022
- CVE-2023-4058330İzleyin
libp2p nodes vulnerable to OOM attack
YüksekCVSS 7,5İstismar yokEPSS %1protocol · libp2p25 Ağu 2023
- CVE-2023-2362630İzleyin
Denial of service when feeding malformed size arguments in go-bitfield
YüksekCVSS 7,5İstismar yokEPSS %1protocol · go-bitfield9 Şub 2023
- CVE-2023-2363130İzleyin
HAMT Decoding Panics in github.com/ipfs/go-unixfsnode
YüksekCVSS 7,5İstismar yokEPSS %1protocol · go-unixfsnode9 Şub 2023
- CVE-2023-2556830İzleyin
Boxo bitswap/server: DOS unbounded persistent memory leak
YüksekCVSS 7,5İstismar yokEPSS %1protocol · boxo10 May 2023
- CVE-2022-258430İzleyin
Panic when decoding invalid blocks in github.com/ipld/go-codec-dagpb
YüksekCVSS 7,5İstismar yokEPSS %1protocol · go-codec-dagpb27 Ara 2022
- CVE-2022-2348730İzleyin
libp2p denial of service vulnerability from lack of resource management
YüksekCVSS 7,5İstismar yokEPSS %1protocol · libp2p7 Ara 2022
- CVE-2022-2348630İzleyin
libp2p-rust denial of service vulnerability from lack of resource management
YüksekCVSS 7,5İstismar yokEPSS %1protocol · libp2p7 Ara 2022
- CVE-2023-2362530İzleyin
Denial of service in HAMT Decoding in go-unixfs
YüksekCVSS 7,5İstismar yokEPSS %1protocol · go-unixfs9 Şub 2023
- CVE-2026-3540530İzleyin
libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers
YüksekCVSS 7,5İstismar yokEPSS %0protocol · libp2p7 Nis 2026
- CVE-2026-3548024İzleyin
go-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headers
OrtaCVSS 6,2İstismar yokEPSS %0protocol · go-ipld-prime7 Nis 2026
- CVE-2022-4754721İzleyin
GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it
OrtaCVSS 5,3İstismar yokEPSS %1protocol · gossipsub19 Ara 2022