THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vrf4-mx87-p53w (high) — libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses

[GHSA] GHSA-vrf4-mx87-p53w (high) — libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses

medgithub_advisoriesPublished 2026-09-17

GHSA-vrf4-mx87-p53w Severity: high CVE: CVE-2026-86039

libp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addresses

### Summary `@libp2p/peer-store` accepts a signed `PeerRecord` whose envelope is signed by one peer but whose payload claims a different peer ID. The vulnerable `consumePeerRecord` path verifies the envelope signature, but does

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vrf4-mx87-p53w