@libp2p/crypto is vulnerable to Denial of Service (DoS)
75
High Risk
The RSA DER decoder trusts element length fields without checking them against the remaining buffer. A malformed length can drive a large synchronous loop and allocation, stalling the Node.js event loop and spiking memory. The fix rejects NaN, negative, and out-of-bounds lengths before parsing.
You are affected if you are using a version that falls within the vulnerable range and your node runs Identify (enabled by default), which DER-decodes a peer's RSA public key before authentication.
@libp2p/crypto is vulnerable to Denial of Service (DoS) in versions 5.0.14 - 5.1.21.
Upgrade the @libp2p/crypto library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.