THREAT OPS › Threat News › [GHSA] GHSA-c3gv-825q-fvmp (high) — libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
[GHSA] GHSA-c3gv-825q-fvmp (high) — libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
GHSA-c3gv-825q-fvmp Severity: high CVE: CVE-2026-86038
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID
### Summary `@libp2p/gossipsub` `StrictSign` validation does not bind a supplied message public key to the claimed `from` peer ID when `from` is an RSA-style peer ID that does not inline its public key. An attacker can set `from` to a victim RSA peer ID, si
Indicators of compromise
- CVE-2026-86038cve
Original source: https://github.com/advisories/GHSA-c3gv-825q-fvmp