VendorsProtocolgossipsuball versions
Vulnerabilities

Protocol Gossipsub

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-12821
Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.
Published 2020-07-07 · Modified
9.8EPSS 0.019
CVE-2022-47547
GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it continuously misbehaves by never forwarding topic messages.
Published 2022-12-19 · Modified
5.3EPSS 0.005