Junglewise Threat Intelligence

CVE-2026-45783: libp2p @libp2p/kad-dht Disk Exhaustion via Unvalidated PUT_VALUE Records

CVE-2026-45783 · Severity: high · CVSS 7.5 · Published 2026-06-10

Vendors: Libp2p, npm.

Executive brief

The @libp2p/kad-dht library is a distributed hash table (DHT) component used in peer-to-peer networking applications. An unauthenticated attacker can crash any DHT server node by flooding it with specially crafted PUT_VALUE messages that bypass validation and fill the disk with invalid data, rendering the node unavailable.

Technical details

The vulnerability stems from two cooperating defects in the JavaScript implementation. First, the verifyRecord function silently succeeds and writes records to the datastore when keys have fewer than 3 slash-delimited parts (after UTF-8 decoding), bypassing validation for legitimate DHT keys (/pk/*, /ipns/*) entirely. Second, the RPC message-handling loop resets its inactivity timeout after every successfully received message with no per-stream message count limit, per-peer byte budget, or rate limiter. An attacker can deliver 4 MB messages repeatedly within the 10-second inactivity window across 32 concurrent streams, achieving unbounded disk exhaustion. No authentication or protocol deviation beyond a crafted key is required; only a standard libp2p TLS handshake is needed. The Go implementation (go-libp2p-kad-dht) is not affected, as it enforces record validation at the RPC layer. A proof-of-concept test is provided in the advisory.

Affected products

  • libp2p @libp2p/kad-dht ≤ 16.2.4

Timeline

  • 2026-05-19: disclosed: Advisory published
  • 2026-05-19: patched: Fix released in version 16.2.6

References