11.0.30
4 years ago
27 days ago
Known vulnerabilities in the @libp2p/floodsub package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@libp2p/floodsub is a libp2p-floodsub, also known as pubsub-flood or just dumbsub, this implementation of pubsub focused on delivering an API for Publish/Subscribe, but with no CastTree Forming (it just floods the network). Affected versions of this package are vulnerable to Missing Release of Memory after Effective Lifetime via the How to fix Missing Release of Memory after Effective Lifetime? Upgrade | <11.0.26 |