THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5hq8-qhww-jm7q (high) — libp2p-quic: Remote panic via certificate expiry race during QUIC handshake

[GHSA] GHSA-5hq8-qhww-jm7q (high) — libp2p-quic: Remote panic via certificate expiry race during QUIC handshake

highgithub_advisoriesPublished 2026-09-15

GHSA-5hq8-qhww-jm7q Severity: high CVE: CVE-2026-61544

libp2p-quic: Remote panic via certificate expiry race during QUIC handshake

### Summary

`libp2p-quic` can panic on an inbound QUIC handshake if a malicious peer presents a valid, short lived libp2p TLS certificate and delays the final TLS 1.3 handshake fragment until the certificate expires.

This is remotely reachable by a network peer and

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5hq8-qhww-jm7q