Skip to main content
Vulnerability Database/CVE-2026-89146

CVE-2026-89146: libp2p-rendezvous DOS Vulnerability

CVE-2026-89146 is a denial of service vulnerability in libp2p-rendezvous that allows attackers to crash client nodes through timer overflow. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-89146 Overview

CVE-2026-89146 is a denial-of-service vulnerability in the libp2p-rendezvous Rust crate through version 0.17.1. The crate implements the rendezvous protocol for the libp2p peer-to-peer networking stack. The flaw stems from missing validation of registration Time-To-Live (TTL) values received in discovery responses. A malicious rendezvous server can return an unbounded TTL that triggers integer overflow during timer arithmetic, crashing the client node process. The vulnerability is classified under CWE-190: Integer Overflow or Wraparound.

Critical Impact

A remote, unauthenticated rendezvous server can cause any connected libp2p client node to panic and terminate, disrupting availability of peer-to-peer services built on the affected crate.

Affected Products

  • libp2p-rendezvous Rust crate versions through 0.17.1
  • libp2p client nodes using the rendezvous discovery protocol
  • Applications built on the rust-libp2p stack that enable the rendezvous client behavior

Discovery Timeline

  • 2026-09-11 - CVE-2026-89146 published to the National Vulnerability Database (NVD)
  • 2026-09-11 - Last updated in NVD database

Technical Details for CVE-2026-89146

Vulnerability Analysis

The libp2p-rendezvous client processes discovery responses from remote rendezvous servers to locate other peers. Each registration record in a discovery response carries a TTL value indicating how long the record remains valid. The client uses this TTL to compute an expiry timer by adding it to the current time.

The client fails to bound or sanity-check the TTL before performing this arithmetic. When a malicious server supplies an unbounded or near-maximum TTL value, the addition overflows in the timer computation path. The resulting arithmetic overflow causes a Rust panic, terminating the client node process. Because the rendezvous protocol operates over the network with no authentication requirement on discovery responses, any server a client queries can trigger the crash.

Root Cause

The root cause is missing input validation on protocol-supplied numeric fields, corresponding to [CWE-190]. The client trusts the TTL value from the discovery response and passes it directly into duration and timer arithmetic. Rust's debug-mode arithmetic panics on overflow, and even in release mode the derived expiry instant is invalid, forcing a panic in downstream timer logic. See the libp2p Rendezvous Client Source for the affected discovery-handling code path.

Attack Vector

Exploitation requires only that a victim client issue a discovery request to an attacker-controlled rendezvous server, or that an attacker operate a malicious server that legitimate clients query as part of normal peer discovery. The attacker responds with a crafted registration entry containing an unbounded TTL. No credentials, user interaction, or prior access to the victim are required. A public proof-of-concept is referenced in the VulnCheck Advisory on libp2p and a GitHub Gist PoC.

A public proof-of-concept demonstrates the crash by returning a discovery response containing a registration record with the maximum representable TTL. No exploit code is reproduced here; refer to the linked advisory for the technical demonstration.

Detection Methods for CVE-2026-89146

Indicators of Compromise

  • Unexpected process termination or panic logs from applications embedding libp2p-rendezvous shortly after issuing a discovery request.
  • Rust panic messages referencing arithmetic overflow, Instant, Duration, or timer expiry within rendezvous client stack frames.
  • Repeated crash-restart cycles of a libp2p node correlated with connections to a specific remote peer identifier acting as a rendezvous server.

Detection Strategies

  • Inspect application logs and crash dumps for Rust panics originating in the libp2p_rendezvous::client module.
  • Capture and inspect rendezvous protocol messages on the wire for registration entries carrying TTL values near u64::MAX or otherwise outside expected operational bounds.
  • Correlate node crashes with the peer identifier of the rendezvous server that returned the last discovery response.

Monitoring Recommendations

  • Track process uptime and restart counts for services embedding rust-libp2p and alert on abnormal restart rates.
  • Log the peer ID and multiaddress of every rendezvous server queried, so crashes can be attributed to specific upstream servers.
  • Forward libp2p application logs to a centralized logging pipeline and alert on panic strings matching timer arithmetic errors.

How to Mitigate CVE-2026-89146

Immediate Actions Required

  • Inventory all applications and services that depend on the libp2p-rendezvous crate, directly or transitively via rust-libp2p.
  • Upgrade to a fixed release of libp2p-rendezvous once published upstream; monitor the libp2p Rust Repository for release notes.
  • Restrict rendezvous client configurations to trusted, operator-controlled rendezvous servers where feasible.
  • Deploy process supervision so that any crash is automatically restarted while remediation is in progress.

Patch Information

At the time of publication, the advisory identifies all versions of libp2p-rendezvous through 0.17.1 as affected. Track the VulnCheck Advisory on libp2p and the upstream libp2p Rust Repository for the fixed version and apply the update across all dependent services.

Workarounds

  • Pin rendezvous discovery to a curated allowlist of trusted server peer IDs and reject responses from untrusted servers.
  • Add a local wrapper that validates registration TTL values against a maximum acceptable bound before they reach the timer computation path.
  • Disable the rendezvous client behavior in rust-libp2p node configurations until a patched crate version is deployed.
bash
# Configuration example: identify vulnerable dependency versions
cargo tree -i libp2p-rendezvous
cargo update -p libp2p-rendezvous

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.