THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c3gv-825q-fvmp (high) — libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID

[GHSA] GHSA-c3gv-825q-fvmp (high) — libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID

medgithub_advisoriesPublished 2026-09-17

GHSA-c3gv-825q-fvmp Severity: high CVE: CVE-2026-86038

libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID

### Summary `@libp2p/gossipsub` `StrictSign` validation does not bind a supplied message public key to the claimed `from` peer ID when `from` is an RSA-style peer ID that does not inline its public key. An attacker can set `from` to a victim RSA peer ID, si

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c3gv-825q-fvmp