Hyperledger
7 CVEs tracked since 2022. Since Sep 2022, none of them reached CISA KEV.
Hyperledger CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-09 | 3 | 0 |
| 2022-10 | null or fewer | |
| 2022-11 | null or fewer | |
| 2022-12 | null or fewer | |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | null or fewer | |
| 2024-01 | 4 | 0 |
Products
The products that kept showing up in Hyperledger's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Hyperledger.
- CVE-2026-53658Fabric CA: LDAP Injection via Unescaped Username in GetUser Filter—
- CVE-2026-45581fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode5.5
- CVE-2026-41586ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCE9.8
- CVE-2025-30147ALTBN128_ADD, ALTBN128_MUL, ALTBN128_PAIRING precompile functions do not check if points are on curve—
- CVE-2024-45244Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.5.3
- CVE-2024-22192Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holders6.5
- CVE-2024-21670CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential6.5
- CVE-2022-31021Unlinkability broken in ursa when verifiers use malicious keys3.3
- CVE-2024-21669Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC9.9
- CVE-2023-46132Crosslinking transaction attack in hyperledger/fabric7.1
- CVE-2022-45196Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the same Channel name. NOTE: the official Fabric with Raft preve...7.5
- CVE-2022-36025Incorrect Conversion between Numeric Types in Besu Ethereum Client9.1
- CVE-2022-31006Hyperledger Indy DOS vulnerability7.5
- CVE-2022-31020Remote code execution in Indy's NODE_UPGRADE transaction8.8
- CVE-2022-36023Remote denial of service in Hyperledger Fabric Gateway7.0
The record
- Peak rank
- #180 in Jan 2024
- Busiest month shown
- Jan 2024, 4 CVEs
- Months with a KEV entry
- 0 since Sep 2022
- Monthly snapshots
- 2 since 2022