This project contains known security vulnerabilities. Find detailed information at the bottom.

Crate libp2p-floodsub

Dependencies

(12 total, 9 outdated, 1 insecure)

CrateRequiredLatestStatus
 bs58^0.2.00.5.1out of date
 bytes^0.41.12.1out of date
 cuckoofilter^0.3.20.5.0out of date
 fnv^1.01.0.7up to date
 futures^0.10.3.34out of date
 libp2p-core^0.10.00.44.0out of date
 protobuf ⚠️^2.33.7.2insecure
 rand^0.60.10.3out of date
 smallvec^0.6.51.16.2out of date
 tokio-codec^0.10.1.2up to date
 tokio-io^0.10.1.13up to date
 unsigned-varint^0.2.10.8.0out of date

Security Vulnerabilities

protobuf: Crash due to uncontrolled recursion in protobuf crate

RUSTSEC-2024-0437

Affected version of this crate did not properly parse unknown fields when parsing a user-supplied input.

This allows an attacker to cause a stack overflow when parsing the mssage on untrusted data.