CVE-2026-89146
libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process to panic when computing the expiry timer.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- CWE
- CWE-190, CWE-617
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- libp2p libp2p-rendezvous
Weakness type
Related vulnerabilities
- CVE-2026-90473 — msgpack-java through 0.9.12 Integer Overflow via MAP32
- CVE-2026-87020 — Orthanc DICOM Server Integer Overflow or Wraparound
- CVE-2026-89158 — PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant...
- CVE-2026-89157 — PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an...
- CVE-2026-88914 — Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser
- CVE-2026-16174 — Netskope Endpoint DLP Driver Integer Overflow Leading to Kernel Pool Overflow
- CVE-2026-88035 — Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver
- CVE-2026-85228 — Integer overflow in tensor buffer validation in Deep Java Library