Two high-severity flaws in the Rust implementation of libp2p allow remote peers to crash applications using the Gossipsub protocol by sending crafted PRUNE control messages with extremely large backoff values. CVE-2026-33040 affects versions prior to 0.49.3, where unchecked time arithmetic in the networking state machine can panic and cause a denial of service, while CVE-2026-34219 affects versions prior to 0.49.4 through improper backoff expiry handling that triggers an Instant + Duration integer overflow during heartbeat processing.
The bugs are reachable over normal Gossipsub peer connectivity, including TCP sessions using Noise with mplex or yamux, and do not require traditional authentication beyond establishing a protocol peer relationship. Both issues are classified under CWE-190 for integer overflow, with the newer advisory also citing CWE-617, and both primarily impact availability by enabling unauthenticated or minimally authenticated remote attackers to force panics in exposed services. Maintainers patched the issues in libp2p-rust versions 0.49.3 and 0.49.4, respectively.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A second Gossipsub denial-of-service flaw involving improper backoff expiry handling and unchecked Instant-plus-Duration arithmetic was patched in libp2p-rust version 0.49.4. The issue affected versions prior to 0.49.4 and could be triggered by a crafted PRUNE control message from a reachable peer.
A denial-of-service vulnerability in the Rust libp2p Gossipsub implementation, caused by unchecked time arithmetic on a crafted PRUNE backoff value, was fixed in libp2p-rust version 0.49.3. The flaw affected versions prior to 0.49.3 and allowed a remote unauthenticated attacker to trigger a panic.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.