Vulnerability DatabaseGHSA-84x2-2qv6-qg56

GHSA-84x2-2qv6-qg56
Rust vulnerability analysis and mitigation

Overview

The Nervos CKB (Common Knowledge Base) network was found to have a critical vulnerability in its P2P protocols due to the absence of rate limiting. This vulnerability, identified as GHSA-84x2-2qv6-qg56, affected versions prior to 0.34.0 of the CKB software. The issue was discovered and disclosed on June 5, 2020, impacting all nodes connected to the CKB P2P network (GitHub Advisory).

Technical details

The vulnerability stems from a design flaw in the P2P protocols where nodes lack proper rate limiting mechanisms. Specifically, in the relay protocol, when a node receives broadcasted transaction hashes (tx_hashes), it marks them in memory to prevent duplicate requests. However, this mechanism can be exploited by generating random transaction hashes, potentially overwhelming the node's memory resources (GitHub Advisory).

Impact

The vulnerability affects all nodes connected to the CKB P2P network, making it a critical security concern. When exploited, it could lead to Denial of Service (DoS) attacks, potentially disrupting the network's normal operation and affecting the overall stability of the Nervos CKB network (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in version 0.34.0 of the CKB software. As a workaround, users are advised to apply rate limiting on the data sent to the CKB P2P port. The fix implemented includes setting up a rate limiter keyed by peer and message type that allows through 30 requests per second, providing a flexible hard cap with buffer (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22698HIGH8.7
  • RustRust
  • sm2
NoNoJan 10, 2026
CVE-2026-22700HIGH7.5
  • RustRust
  • sm2
NoNoJan 10, 2026
CVE-2026-22699HIGH7.5
  • RustRust
  • sm2
NoNoJan 10, 2026
CVE-2026-22705MEDIUM6.4
  • RustRust
  • ml-dsa
NoYesJan 10, 2026
CVE-2025-15504MEDIUM4.8
  • PythonPython
  • lief
NoYesJan 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management