npm package report

Is @libp2p/gossipsub safe?

3 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
0.20%

chance of exploitation in the next 30 days

xyz score
3.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-c3gv-825q-fvmp, the advisory selected below

// advisories

GHSA-c3gv-825q-fvmp

HIGHCVE-2026-86038

@libp2p/gossipsub StrictSign validation does not bind a supplied message public key to the claimed from peer ID when from is an RSA-style peer ID that does not inline its public key. An attacker can set from to a victim RSA peer ID, sign the message with the attacker's own private key, include the attacker's public key in msg.key, and have the message accepted as a valid signed message from the vi

Affected
>= 15.0.0, < 16.0.5
Fixed in
16.0.5
Weakness
CWE-345
Published
2026-09-17
Source
github

GHSANVDMITREreferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 02:53 UTC. The most recent advisory here was published 2026-09-17. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @libp2p/gossipsub safe? npm package security report | CyberXYZ