CVE-2026-49866 | libp2p up to 15.0.23 Gossipsub message/decodeRpc.ts infinite loop
A vulnerability was found in libp2p. It has been rated as problematic. This affects an unknown part of the file message/decodeRpc.ts of the component Gossipsub. The manipulation leads to infinite loop.
This vulnerability is uniquely identified as CVE-2026-49866. The attack is possible to be carried out remotely. No exploit exists.