cargo package report

Is libp2p-rendezvous safe?

2 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
0.40%

chance of exploitation in the next 30 days

xyz score
3.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-cqfx-gf56-8x59, the advisory selected below

// advisories

GHSA-cqfx-gf56-8x59

HIGHCVE-2026-35405

Thelibp2p-rendezvous server has no limit on how many namespaces a single peer can register. A malicious peer can repeatedly register unique namespaces in a loop, and the server accepts the requests, allocating memory for each registration without pushback. If an attacker continues submitting malicous requests for long enough, (or with multiple sybil peers) the server process crashes due to OOM.

Affected
>=0, <0.17.1, < 0.17.1
Fixed in
0.17.1
Weakness
CWE-770
Published
2026-04-04
Source
osv

NVDMITREOSV


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so cargo packages are not covered.


Checked 2026-09-22 at 00:42 UTC. The most recent advisory here was published 2026-04-04. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is libp2p-rendezvous safe? cargo package security report | CyberXYZ