github.com/celestiaorg/celestia-core is vulnerable to Denial of Service (DoS) via Resource Exhaustion
30
Low Risk
Affected versions of this package allow malicious peers to send Txs protobuf messages containing excessive or zero-length transactions, which are not properly validated. An attacker can exploit this by flooding nodes with messages packed with thousands of empty entries, triggering repeated SHA256 hashing, memory allocations, map operations, and CheckTx calls, leading to uncontrolled CPU and memory consumption. This resource exhaustion can degrade performance or cause out-of-memory crashes, effectively resulting in a denial-of-service condition for honest nodes.
You are affected if you are using a version that falls within the vulnerable range.
github.com/celestiaorg/celestia-core is vulnerable to Denial of Service (DoS) via Resource Exhaustion in versions 0.39.0 - 0.39.24.
Upgrade the github.com/celestiaorg/celestia-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant