CVE-2026-35480
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Prior to 0.22.0, the DAG-CBOR decoder uses collection sizes declared in CBOR headers as Go preallocation hints for maps and lists. The decoder does not cap these size hints or account for their cost in its allocation budget, allowing small payloads to cause excessive memory allocation. This vulnerability is fixed in 0.22.0.
Published:Apr 7, 2026
Last Modified:Apr 17, 2026
EPS:Apr 7, 2026
EPSS Score:0.00017
CVSS Score:6.2
Affected Products
Vendor
Product
Action
Vendor
Ipld
Product
Go-ipld-prime
Ipld
Go-ipld-prime
Vendor
Protocol
Product
Go-ipld-prime
Protocol
Go-ipld-prime
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
