@libp2p/floodsub@5.0.0

libp2p-floodsub, also known as pubsub-flood or just dumbsub, this implementation of pubsub focused on delivering an API for Publish/Subscribe, but with no CastTree Forming (it just floods the network).

  • latest version

    11.0.30

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    27 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @libp2p/floodsub package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Missing Release of Memory after Effective Lifetime

    @libp2p/floodsub is a libp2p-floodsub, also known as pubsub-flood or just dumbsub, this implementation of pubsub focused on delivering an API for Publish/Subscribe, but with no CastTree Forming (it just floods the network).

    Affected versions of this package are vulnerable to Missing Release of Memory after Effective Lifetime via the PeerStreams.attachInboundStream process. An attacker can exhaust CPU resources, cause memory exhaustion, and render the node unavailable by sending specially crafted unauthenticated RPC frames that decode into a large number of empty or unique-topic subscription entries, leading to event loop blocking and persistent memory growth.

    How to fix Missing Release of Memory after Effective Lifetime?

    Upgrade @libp2p/floodsub to version 11.0.26 or higher.

    <11.0.26