CVE Tools

Hyperledger

7 CVEs tracked since 2022. Since Sep 2022, none of them reached CISA KEV.

Hyperledger CVEs per month

Sep 2022 to Jan 2024. Point at a month, or focus the strip and use the arrow keys.
Hyperledger CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-0930
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-0140

Products

The products that kept showing up in Hyperledger's monthly top three, with their CVEs summed over those months.

  1. Ursa31 month
  2. Indy-node21 month
  3. Aries Cloud Agent11 month
  4. Aries-cloudagent-python11 month
  5. Besu11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Hyperledger.

  1. CVE-2026-53658Fabric CA: LDAP Injection via Unescaped Username in GetUser Filter—
  2. CVE-2026-45581fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode5.5
  3. CVE-2026-41586ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCE9.8
  4. CVE-2025-30147ALTBN128_ADD, ALTBN128_MUL, ALTBN128_PAIRING precompile functions do not check if points are on curve—
  5. CVE-2024-45244Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.5.3
  6. CVE-2024-22192Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holders6.5
  7. CVE-2024-21670CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential6.5
  8. CVE-2022-31021Unlinkability broken in ursa when verifiers use malicious keys3.3
  9. CVE-2024-21669Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC9.9
  10. CVE-2023-46132Crosslinking transaction attack in hyperledger/fabric7.1
  11. CVE-2022-45196Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the same Channel name. NOTE: the official Fabric with Raft preve...7.5
  12. CVE-2022-36025Incorrect Conversion between Numeric Types in Besu Ethereum Client9.1
  13. CVE-2022-31006Hyperledger Indy DOS vulnerability7.5
  14. CVE-2022-31020Remote code execution in Indy's NODE_UPGRADE transaction8.8
  15. CVE-2022-36023Remote denial of service in Hyperledger Fabric Gateway7.0

The record

Peak rank
#180 in Jan 2024
Busiest month shown
Jan 2024, 4 CVEs
Months with a KEV entry
0 since Sep 2022
Monthly snapshots
2 since 2022
Hyperledger's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store