CVE-2026-89146 Overview
CVE-2026-89146 is a denial-of-service vulnerability in the libp2p-rendezvous Rust crate through version 0.17.1. The crate implements the rendezvous protocol for the libp2p peer-to-peer networking stack. The flaw stems from missing validation of registration Time-To-Live (TTL) values received in discovery responses. A malicious rendezvous server can return an unbounded TTL that triggers integer overflow during timer arithmetic, crashing the client node process. The vulnerability is classified under CWE-190: Integer Overflow or Wraparound.
Critical Impact
A remote, unauthenticated rendezvous server can cause any connected libp2p client node to panic and terminate, disrupting availability of peer-to-peer services built on the affected crate.
Affected Products
- libp2p-rendezvous Rust crate versions through 0.17.1
- libp2p client nodes using the rendezvous discovery protocol
- Applications built on the rust-libp2p stack that enable the rendezvous client behavior
Discovery Timeline
- 2026-09-11 - CVE-2026-89146 published to the National Vulnerability Database (NVD)
- 2026-09-11 - Last updated in NVD database
Technical Details for CVE-2026-89146
Vulnerability Analysis
The libp2p-rendezvous client processes discovery responses from remote rendezvous servers to locate other peers. Each registration record in a discovery response carries a TTL value indicating how long the record remains valid. The client uses this TTL to compute an expiry timer by adding it to the current time.
The client fails to bound or sanity-check the TTL before performing this arithmetic. When a malicious server supplies an unbounded or near-maximum TTL value, the addition overflows in the timer computation path. The resulting arithmetic overflow causes a Rust panic, terminating the client node process. Because the rendezvous protocol operates over the network with no authentication requirement on discovery responses, any server a client queries can trigger the crash.
Root Cause
The root cause is missing input validation on protocol-supplied numeric fields, corresponding to [CWE-190]. The client trusts the TTL value from the discovery response and passes it directly into duration and timer arithmetic. Rust's debug-mode arithmetic panics on overflow, and even in release mode the derived expiry instant is invalid, forcing a panic in downstream timer logic. See the libp2p Rendezvous Client Source for the affected discovery-handling code path.
Attack Vector
Exploitation requires only that a victim client issue a discovery request to an attacker-controlled rendezvous server, or that an attacker operate a malicious server that legitimate clients query as part of normal peer discovery. The attacker responds with a crafted registration entry containing an unbounded TTL. No credentials, user interaction, or prior access to the victim are required. A public proof-of-concept is referenced in the VulnCheck Advisory on libp2p and a GitHub Gist PoC.
A public proof-of-concept demonstrates the crash by returning a discovery response containing a registration record with the maximum representable TTL. No exploit code is reproduced here; refer to the linked advisory for the technical demonstration.
Detection Methods for CVE-2026-89146
Indicators of Compromise
- Unexpected process termination or panic logs from applications embedding libp2p-rendezvous shortly after issuing a discovery request.
- Rust panic messages referencing arithmetic overflow, Instant, Duration, or timer expiry within rendezvous client stack frames.
- Repeated crash-restart cycles of a libp2p node correlated with connections to a specific remote peer identifier acting as a rendezvous server.
Detection Strategies
- Inspect application logs and crash dumps for Rust panics originating in the libp2p_rendezvous::client module.
- Capture and inspect rendezvous protocol messages on the wire for registration entries carrying TTL values near u64::MAX or otherwise outside expected operational bounds.
- Correlate node crashes with the peer identifier of the rendezvous server that returned the last discovery response.
Monitoring Recommendations
- Track process uptime and restart counts for services embedding rust-libp2p and alert on abnormal restart rates.
- Log the peer ID and multiaddress of every rendezvous server queried, so crashes can be attributed to specific upstream servers.
- Forward libp2p application logs to a centralized logging pipeline and alert on panic strings matching timer arithmetic errors.
How to Mitigate CVE-2026-89146
Immediate Actions Required
- Inventory all applications and services that depend on the libp2p-rendezvous crate, directly or transitively via rust-libp2p.
- Upgrade to a fixed release of libp2p-rendezvous once published upstream; monitor the libp2p Rust Repository for release notes.
- Restrict rendezvous client configurations to trusted, operator-controlled rendezvous servers where feasible.
- Deploy process supervision so that any crash is automatically restarted while remediation is in progress.
Patch Information
At the time of publication, the advisory identifies all versions of libp2p-rendezvous through 0.17.1 as affected. Track the VulnCheck Advisory on libp2p and the upstream libp2p Rust Repository for the fixed version and apply the update across all dependent services.
Workarounds
- Pin rendezvous discovery to a curated allowlist of trusted server peer IDs and reject responses from untrusted servers.
- Add a local wrapper that validates registration TTL values against a maximum acceptable bound before they reach the timer computation path.
- Disable the rendezvous client behavior in rust-libp2p node configurations until a patched crate version is deployed.
# Configuration example: identify vulnerable dependency versions
cargo tree -i libp2p-rendezvous
cargo update -p libp2p-rendezvous
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.