NRDAX-T0331 - Unbounded Stream Backpressure OOM
Connection exhaustion (also memory amplification) · P2P and gossip · no bound · active · first seen 2026-07-01
provenance: Reproduced in NullRabbit's attack-reproduction pipeline
mechanism
CVE-2022-23492/CVE-2022-23486: libp2p stream/connection exhaustion (no backpressure) → OOM
live exposure
No exposure data. Slashr ↗ has no risk signal mapped to this technique yet — absence of data is not absence of exposure.
instances (1)
| chain | primitive | fidelity | origin | reproducer (bundle) | source |
|---|---|---|---|---|---|
| libp2p | libp2p_stream_exhaustion | lab | reverse-engineered-cve | libp2p_stream_exhaustion | GHSA-j7qp-mfxf-8xjw ↗ |
references
ghsa: GHSA-qfwj-vfxf-92j2
related (Connection exhaustion)
NRDAX-T0041 - Cross-Chain Peer Pool Pollution active NRDAX-T0064 - Endpoint Concurrency Cap Exhaustion active NRDAX-T0099 - Half-Open Handshake Slowloris active NRDAX-T0214 - Protocol Message Flood Unbounded Goroutine active NRDAX-T0225 - QUIC Control Frame Flood active NRDAX-T0246 - Rate-Limit Key Confusion active NRDAX-T0261 - RPC Request Flood active NRDAX-T0291 - Subscription Permit Exhaustion active
cite
https://nrdax.com/techniques/NRDAX-T0331
plain
NRDAX Registry. Technique NRDAX-T0331.
bibtex
@misc{nrdax_NRDAX_T0331,
title = {Unbounded Stream Backpressure OOM (NRDAX-T0331)},
howpublished = {NRDAX Registry},
url = {https://nrdax.com/techniques/NRDAX-T0331},
} json (csl)
{
"id": "nrdax-NRDAX-T0331",
"type": "dataset",
"title": "Unbounded Stream Backpressure OOM (NRDAX-T0331)",
"URL": "https://nrdax.com/techniques/NRDAX-T0331",
"publisher": "NRDAX Registry"
} badge
[](https://nrdax.com/techniques/NRDAX-T0331-unbounded-stream-backpressure-oom)
use from the CLI
Retrieve or cite this technique from a script or the terminal with the NRDAX Python library & CLI.
nrdax get NRDAX-T0331 nrdax cite NRDAX-T0331 --format bibtex