GHSA-c3gv-825q-fvmp
HIGHCVE-2026-86038@libp2p/gossipsub StrictSign validation does not bind a supplied message public key to the claimed from peer ID when from is an RSA-style peer ID that does not inline its public key. An attacker can set from to a victim RSA peer ID, sign the message with the attacker's own private key, include the attacker's public key in msg.key, and have the message accepted as a valid signed message from the vi
- Affected
- >= 15.0.0, < 16.0.5
- Fixed in
- 16.0.5
- Weakness
- CWE-345
- Published
- 2026-09-17
- Source
- github