CVE-2026-34062 PUBLISHED

Nimiq has Allocation of Resources Without Limits or Throttling in its libp2p request/response

Assigner: GitHub_M
Reserved: 25.03.2026 Published: 22.04.2026 Updated: 22.04.2026

nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, MessageCodec::read_request and read_response call read_to_end() on inbound substreams, so a remote peer can send only a partial frame and keep the substream open. because Behaviour::new also sets with_max_concurrent_streams(1000), the node exposes a much larger stalled-slot budget than the library default. The patch for this vulnerability is formally released as part of v1.3.0. No known workarounds are available.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS Score: 5.3

Product Status

Vendor nimiq
Product network-libp2p
Versions
  • Version < 1.3.0 is affected

References

Problem Types

  • CWE-770: Allocation of Resources Without Limits or Throttling CWE