VDB
Sign up
HIGH7.5

GHSA-4q4x-67hx-5mpg

Failure to properly verify ed25519 signatures in libp2p-core

Details

Affected versions of this crate did not properly verify ed25519 signatures. Any signature with a correct length was considered valid. This allows an attacker to impersonate any node identity.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/libp2p-core
Introduced in: 0Fixed in: 0.8.1

Upgrade libp2p-core to 0.8.1 or newer (ecosystem crates.io).

References