py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxer/yamux/yamux.py reads an attacker-controlled 32-bit DATA frame length with read_exactly() before validating it against MAX_WINDOW_SIZE or checking whether stream_id exists. A peer that completes the standard Noise handshake can send a 12-byte frame declaring a 0xFFFFFFFF body and then withhold the body, causing the sequential yamux read loop used by the default new_host() configuration to block and preventing every stream on that connection from making progress. No fixed version is available as of this review.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-13 18:18
Updated : 2026-08-13 19:17
NVD link : CVE-2026-73568
Mitre link : CVE-2026-73568
CVE.ORG link : CVE-2026-73568
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption
