
The foundation said AI-assisted red teaming uncovered and helped patch CVE-2026-34219, a high-severity Gossipsub flaw that could let unauthenticated remote peers crash vulnerable nodes and disrupt validators.
Ethereum Foundation researchers said AI agents used in protocol-security red teaming uncovered CVE-2026-34219, a remotely triggerable panic in libp2p’s Gossipsub component that was later patched in libp2p-gossipsub v0.49.4. External vulnerability listings cited in the reporting described the high-severity denial-of-service flaw as allowing an unauthenticated peer to crash vulnerable consensus, validator-related and other affected nodes with a crafted PRUNE control message, while the foundation said the case also underscored the need for human triage and verification because AI systems still produce false positives and impractical or duplicate findings.