CVE-2026-61544: CWE-248: Uncaught Exception in libp2p rust-libp2p
A vulnerability in libp2p-rust prior to version 0.13.1 allows a panic during an inbound QUIC handshake if a remote peer presents a valid short-lived TLS certificate that expires before the final TLS 1.3 handshake fragment is received. This causes the application using libp2p-quic to terminate unexpectedly.
AI Analysis
Technical Summary
The libp2p-rust implementation of the libp2p networking stack had a flaw in versions before 0.13.1 where libp2p-quic could panic during an inbound QUIC handshake. Specifically, when a remote peer presented a valid short-lived libp2p TLS certificate that expired before the final TLS 1.3 handshake fragment arrived, the code path in transports/quic/src/connection/connecting.rs called libp2p_tls::certificate::parse twice. The second call used expect on the result, which could fail if the certificate had expired by then, causing the application to panic and terminate any listener exposing libp2p-quic. This issue is tracked as CVE-2026-61544 and is fixed in version 0.13.1.
Potential Impact
Applications using libp2p-quic versions prior to 0.13.1 are vulnerable to unexpected termination (panic) during inbound QUIC handshakes when presented with a short-lived TLS certificate that expires during the handshake process. This can cause denial of service by crashing the application exposing the affected listener.
Mitigation Recommendations
Upgrade libp2p-rust to version 0.13.1 or later, where this vulnerability is fixed. No other mitigation is indicated.
CVE-2026-61544: CWE-248: Uncaught Exception in libp2p rust-libp2p
Description
A vulnerability in libp2p-rust prior to version 0.13.1 allows a panic during an inbound QUIC handshake if a remote peer presents a valid short-lived TLS certificate that expires before the final TLS 1.3 handshake fragment is received. This causes the application using libp2p-quic to terminate unexpectedly.
CVSS v4.0
Score 8.2high
Affected software
libp2p
rust-libp2p
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The libp2p-rust implementation of the libp2p networking stack had a flaw in versions before 0.13.1 where libp2p-quic could panic during an inbound QUIC handshake. Specifically, when a remote peer presented a valid short-lived libp2p TLS certificate that expired before the final TLS 1.3 handshake fragment arrived, the code path in transports/quic/src/connection/connecting.rs called libp2p_tls::certificate::parse twice. The second call used expect on the result, which could fail if the certificate had expired by then, causing the application to panic and terminate any listener exposing libp2p-quic. This issue is tracked as CVE-2026-61544 and is fixed in version 0.13.1.
Potential Impact
Applications using libp2p-quic versions prior to 0.13.1 are vulnerable to unexpected termination (panic) during inbound QUIC handshakes when presented with a short-lived TLS certificate that expires during the handshake process. This can cause denial of service by crashing the application exposing the affected listener.
Mitigation Recommendations
Upgrade libp2p-rust to version 0.13.1 or later, where this vulnerability is fixed. No other mitigation is indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-10T16:27:03.093Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa9a43e55bf5e2cf54f7f0a
Added to database: 09/15/2026, 20:02:06 UTC
Last enriched: 09/15/2026, 20:16:27 UTC
Last updated: 09/15/2026, 20:16:27 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.