GHSA-mcq2-w56r-5w2w
HIGHgo-ipfs nodes with versions 0.10.0, 0.11.0, 0.12.0, or 0.12.1 can crash when trying to traverse certain malformed graphs due to an issue in the go-codec-dagpb dependency. Vulnerable nodes that work with these malformed graphs may crash leading to denial-of-service risks.
- Affected
- < 0.11.1
- Fixed in
- 0.11.1
- Published
- 2022-04-08
- Source
- github