Skip to content

Vulnerability in iotex-core project #4821

Description

@ankitdn

While working on iotex-core project, I scanned the dependency manifest and found that it uses a vulnerable version of github.com/ipld/go-ipld-prime. The scan revealed an unbounded memory allocation issue in the DAG-CBOR decoder, where crafted payloads can trigger excessive memory usage, potentially leading to a denial of service.

CVE Report
CVE Link

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions