FlawAtlas
Search the atlas
CVE-2023-26248 Moderate

Content Censorship in the InterPlanetary File System (IPFS) via Kademlia DHT abuse in github.com/libp2p/go-libp2p-kad-dht

Content Censorship in the InterPlanetary File System (IPFS) via Kademlia DHT abuse in github.com/libp2p/go-libp2p-kad-dht

Exploit probability 0.2%
Published December 12, 2024
Required by Not available
Last source change July 1, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/libp2p/go-libp2p-kad-dht
Go github.com/libp2p/go-libp2p-kad-dht

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-mqr9-hjr8-2m9w

The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information for content (i.e., information about who holds the content) to be stored by peers whose peer IDs have a small DHT distance from the content ID. This allows an attacker to censor content by generating many Sybil peers whose peer IDs have a small distance from the content ID, thus hijacking the content resolution process.

View original source
Open Source Vulnerabilities GO-2024-3218

Content Censorship in the InterPlanetary File System (IPFS) via Kademlia DHT abuse in github.com/libp2p/go-libp2p-kad-dht

View original source

05 / REFERENCES

Further evidence