THREAT OPS › Threat News › [GHSA] GHSA-5hq8-qhww-jm7q (high) — libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
[GHSA] GHSA-5hq8-qhww-jm7q (high) — libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
GHSA-5hq8-qhww-jm7q Severity: high CVE: CVE-2026-61544
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
### Summary
`libp2p-quic` can panic on an inbound QUIC handshake if a malicious peer presents a valid, short lived libp2p TLS certificate and delays the final TLS 1.3 handshake fragment until the certificate expires.
This is remotely reachable by a network peer and
Indicators of compromise
- 969b707bf1177ebebd1febc285c3fd22793b95c5sha1
- CVE-2026-61544cve
Original source: https://github.com/advisories/GHSA-5hq8-qhww-jm7q