Request/Response inbound failure retains stale `response_channels` state after attacker-controlled failed requests
Fixed in: nimiq-network-libp2p v1.3.0
details
- Finding IDs
- F-NIMIQ-REQRES-INBOUNDLEAK-001
- GHSA
- GHSA-w5f8-87h2-m573
- Status
- patched
- Fixed in
- nimiq-network-libp2p v1.3.0
- Recorded credit
- finder: @1seal
- Note
- GHSA-w5f8-87h2-m573; patched in v1.3.0 via PR #3665
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
- Upstream title
- Request/Response inbound failure retains stale `response_channels` state after attacker-controlled failed requests
- Upstream CWE
- CWE-772
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: finder (accepted)
F-NIMIQ-REQRES-INBOUNDLEAK-001: Resource limits. Inbound request channels retain resources after their useful lifetime. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-NIMIQ-REQRES-INBOUNDLEAK-001
Security area (1seal assessment): Availability. Inbound request channels retain resources after their useful lifetime. Reviewed 24 Sep 2026.