libp2p@0.7.0

libp2p: The Python implementation of the libp2p networking stack

  • latest version

    0.7.0

  • first published

    7 years ago

  • latest version published

    16 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the libp2p package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Validation of Specified Quantity in Input

    libp2p is a libp2p: The Python implementation of the libp2p networking stack

    Affected versions of this package are vulnerable to Improper Validation of Specified Quantity in Input through the handle_incoming process. An attacker can cause the read loop to block indefinitely by sending a crafted frame with an oversized length field after completing a standard handshake, resulting in all streams on the connection becoming unresponsive.

    How to fix Improper Validation of Specified Quantity in Input?

    A fix was pushed into the master branch but not yet published.

    [0,)