github.com/ipfs/kubo
An IPFS implementation in Go
Activity
- Latest release
- Apr 20, 2026
- Total releases
- 50
- Cadence
- ~2 months
- Last 12 months
- 6
Reach
- Stars
- 17.1k
Details
- First release
- Feb 27, 2015
| Version | Released | |
|---|---|---|
v0.41.0-rc2
pre
|
v0.41.0-rc2
pre
Dependencies (90)
+ 82 more |
|
v0.41.0-rc1
pre
|
v0.41.0-rc1
pre
Dependencies (90)
+ 82 more |
|
v0.39.0
minor
|
v0.39.0
minor
Dependencies (91)
+ 83 more |
|
v0.39.0-rc1
pre
|
v0.39.0-rc1
pre
Dependencies (91)
+ 83 more |
|
v0.38.0
minor
|
v0.38.0
minor
Dependencies (90)
+ 82 more |
|
v0.38.0-rc2
pre
|
v0.38.0-rc2
pre
Dependencies (90)
+ 82 more |
|
v0.35.0-rc1
pre
|
v0.35.0-rc1
pre
Dependencies (90)
+ 82 more |
|
v0.34.1
minor
|
v0.34.1
minor
Dependencies (90)
+ 82 more |
|
v0.32.0-rc2
pre
|
v0.32.0-rc2
pre
Dependencies (91)
+ 83 more |
|
v0.31.0-rc1
pre
|
v0.31.0-rc1
pre
Dependencies (90)
+ 82 more |
|
v0.30.0
minor
|
v0.30.0
minor
Dependencies (88)
+ 80 more |
|
v0.30.0-rc3
pre
|
v0.30.0-rc3
pre
Dependencies (88)
+ 80 more |
|
v0.30.0-rc2
pre
|
v0.30.0-rc2
pre
Dependencies (88)
+ 80 more |
|
v0.29.0
minor
|
v0.29.0
minor
Dependencies (87)
+ 79 more |
|
v0.27.0-rc1
pre
|
v0.27.0-rc1
pre
Dependencies (88)
+ 80 more |
|
v0.21.0-rc2
pre
|
v0.21.0-rc2
pre
Dependencies (85)
+ 77 more |
|
v0.19.2
minor
|
v0.19.2
minor
Dependencies (108)
+ 100 more |
|
v0.19.0-rc1
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.19.0-rc1
pre
Dependencies (108)
+ 100 more |
|
v0.18.0-rc1
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.18.0-rc1
pre
Dependencies (113)
+ 105 more |
|
v0.17.0
minor
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.17.0
minor
Dependencies (112)
+ 104 more |
|
v0.16.0
minor
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.16.0
minor
Dependencies (113)
+ 105 more |
|
v0.13.0
minor
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.13.0
minor
Dependencies (123)
+ 115 more |
|
v0.13.0-rc1
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.13.0-rc1
pre
Dependencies (121)
+ 113 more |
|
v0.12.1
minor
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.12.1
minor
Dependencies (108)
+ 100 more |
|
v0.11.0-rc2
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.11.0-rc2
pre
Dependencies (108)
+ 100 more |
|
v0.9.0-rc2
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.9.0-rc2
pre
Dependencies (103)
+ 95 more |
|
v0.5.0-rc4
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.5.0-rc4
pre
Dependencies (99)
+ 91 more |
|
v0.5.0-rc2
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.5.0-rc2
pre
Dependencies (99)
+ 91 more |
|
v0.4.23-rc2
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.23-rc2
pre
Dependencies (103)
+ 95 more |
|
v0.4.22
patch
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.22
patch
Dependencies (110)
+ 102 more |
|
v0.4.21-rc1
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.21-rc1
pre
Dependencies (110)
+ 102 more |
|
v0.4.18-rc1
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.18-rc1
pre
|
|
v0.4.17
patch
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.17
patch
|
|
v0.4.16-rc1
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.16-rc1
pre
|
|
v0.4.14-rc2
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.14-rc2
pre
|
|
v0.4.12
patch
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.12
patch
|
|
v0.4.12-rc1
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.12-rc1
pre
|
|
v0.4.11
patch
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.11
patch
|
|
v0.4.11-rc2
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.11-rc2
pre
|
|
v0.4.8
patch
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.8
patch
|
|
v0.4.5-rc4
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.5-rc4
pre
|
|
v0.4.5-rc3
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.5-rc3
pre
|
|
v0.4.5-pre2
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.5-pre2
pre
|
|
v0.4.5-pre1
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.5-pre1
pre
|
|
v0.4.3-rc3
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.3-rc3
pre
|
|
v0.4.3-rc2
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.3-rc2
pre
|
|
v0.4.2
minor
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.4.2
minor
|
|
v0.3.2
initial
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.3.2
initial
|
|
v0.2.3-buildfails
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.2.3-buildfails
pre
|
|
v0.2.2-buildfails
pre
1 CVE
GHSA-qvqg-6rp8-4p9h
May 11, 2023
github.com/ipfs/kubo affected by DOS Bitswap unbounded persistent memory leak
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactAn attacker is able allocate arbitrarily many bytes in the Bitswap server by sending many This affects users accepting or connecting untrusted connections such as by running in the public swarm and no pnet config. Nodes that are not publicly reachable but connects to untrusted nodes are also vulnerable to the untrusted nodes being connected to since libp2p connections are blindly bidirectional. Patches
WorkaroundsUse PNET, swarm filters or resource manager allows list to block untrusted connections. Note that using the resource manager will disrupt both client and server features because the bitswap protocol is a message based protocol mixing requests and responses. References
Fixed in
0.19.0
References Updated May 11, 2023 · Source: OSV.dev |
v0.2.2-buildfails
pre
|