-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The key vulnerability stemmed from improper DHT key validation in escapeDhtKey. The patch shows:
This function directly processed attacker-controlled DHT keys using vulnerable decoding, making it the primary entry point for poisoning routing tables through malicious key injections. The pre-patch logic's len(parts)==1 case and base58 usage created the bypass vector.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/ipfs/go-ipfs | go | < 0.7.0 | 0.7.0 |
Ongoing coverage of React2Shell