GHSA-876p-8259-xjgg
HIGHCVE-2023-39533A malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verification of the large key. This vulnerability is present in the core/crypto module of go-libp2p and can occur during the Noise handshake and the libp2p x509 extension verification step.
- Affected
- >=0, <0.27.8, >=0.28.0, <0.28.2, >=0.29.0, <0.29.1
- Fixed in
- 0.29.1
- Published
- 2023-08-09
- Source
- github