github.com/libp2p/go-libp2p is vulnerable to Race Condition
50
Medium Risk
Affected versions of this package are vulnerable to a race condition, causing concurrent requests to reuse the same HMAC information. This flaw can compromise the integrity of the HMAC mechanism, potentially exposing sensitive data or allowing unauthorized access.
You are affected if you are using a version that falls within the vulnerable range.
github.com/libp2p/go-libp2p is vulnerable to Race Condition in versions 0.37.0 - 0.38.0.
Upgrade the github.com/libp2p/go-libp2p library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant