Skip to content

[GHSA-876p-8259-xjgg] libp2p nodes vulnerable to attack using large RSA keys - #9151

Open
simonmorley wants to merge 1 commit into
github:simonmorley/advisory-improvement-9151from
simonmorley:simonmorley-GHSA-876p-8259-xjgg
Open

[GHSA-876p-8259-xjgg] libp2p nodes vulnerable to attack using large RSA keys#9151
simonmorley wants to merge 1 commit into
github:simonmorley/advisory-improvement-9151from
simonmorley:simonmorley-GHSA-876p-8259-xjgg

Conversation

@simonmorley

Copy link
Copy Markdown

Updates

  • References

Comments
NRDAX-T0205 (Pre-Handshake Crypto CPU Burn) catalogues the mechanism class this advisory describes: asymmetric cryptography performed on attacker-supplied material before any authentication or authorisation check has run. The registry entry links the sibling implementations of that same condition across independent stacks, including CometBFT's SecretConnection STS exchange, which performs its X25519 and ed25519 work ahead of the nodeID allowlist check. The reference gives a reader of this advisory the class the go-libp2p RSA case belongs to, and the other public instances clustered against it.

@github-actions
github-actions Bot changed the base branch from main to simonmorley/advisory-improvement-9151 August 17, 2026 16:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant