hyperledger records
11 published records for vendor hyperledger.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 45.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-347 Improper Verification of Cryptographic Signature2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm2
- CWE-20 Improper Input Validation2
- CWE-502 Deserialization of Untrusted Data1
- CWE-670 Always-Incorrect Control Flow Implementation1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2026-41586No exploit | ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCEhyperledger · fabric · CWE-502 | Critical9.3 | — | 0.6% | May 7, 2026 |
35Monitor | CVE-2024-21669No exploit | Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VChyperledger · aries cloud agent · CWE-347 | High8.8 | — | 0.6% | Jan 11, 2024 |
32Monitor | CVE-2024-21670No exploit | CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credentialhyperledger · ursa · CWE-327 | High8.1 | — | 0.3% | Jan 16, 2024 |
31Monitor | CVE-2022-31121No exploit | Improper Input Validation in fabric hyperledgerhyperledger · fabric · CWE-20 | High7.5 | — | 2.1% | Jul 7, 2022 |
30Monitor | CVE-2022-45196No exploit | Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the samhyperledger · fabric · CWE-670 | High7.5 | — | 0.9% | Nov 12, 2022 |
30Monitor | CVE-2018-3756No exploit | Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transacthyperledger · iroha · CWE-347 | High7.5 | — | 0.8% | Jun 1, 2018 |
26Monitor | CVE-2023-46132No exploit | Crosslinking transaction attack in hyperledger/fabrichyperledger · fabric · CWE-362 | Medium6.5 | — | 0.5% | Nov 14, 2023 |
26Monitor | CVE-2024-22192No exploit | Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holdershyperledger · ursa · CWE-327 | Medium6.5 | — | 0.3% | Jan 16, 2024 |
21Monitor | CVE-2022-36023No exploit | Remote denial of service in Hyperledger Fabric Gatewayhyperledger · fabric · CWE-20 | Medium5.3 | — | 1.1% | Aug 18, 2022 |
21Monitor | CVE-2024-45244Proof of concept | Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.hyperledger · fabric · CWE-294 | Medium5.3 | — | 0.6% | Aug 24, 2024 |
21Monitor | CVE-2022-31021No exploit | Unlinkability broken in ursa when verifiers use malicious keyshyperledger · ursa · CWE-829 | Medium5.3 | — | 0.4% | Jan 16, 2024 |
- CVE-2026-4158637Monitor
ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCE
CriticalCVSS 9.3No exploitEPSS 1%hyperledger · fabricMay 7, 2026
- CVE-2024-2166935Monitor
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
HighCVSS 8.8No exploitEPSS 1%hyperledger · aries cloud agentJan 11, 2024
- CVE-2024-2167032Monitor
CL-Signatures Revocation Scheme in Ursa has flaws that allow a holder to demonstrate non-revocation of a revoked credential
HighCVSS 8.1No exploitEPSS 0%hyperledger · ursaJan 16, 2024
- CVE-2022-3112131Monitor
Improper Input Validation in fabric hyperledger
HighCVSS 7.5No exploitEPSS 2%hyperledger · fabricJul 7, 2022
- CVE-2022-4519630Monitor
Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the sam
HighCVSS 7.5No exploitEPSS 1%hyperledger · fabricNov 12, 2022
- CVE-2018-375630Monitor
Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transact
HighCVSS 7.5No exploitEPSS 1%hyperledger · irohaJun 1, 2018
- CVE-2023-4613226Monitor
Crosslinking transaction attack in hyperledger/fabric
MediumCVSS 6.5No exploitEPSS 1%hyperledger · fabricNov 14, 2023
- CVE-2024-2219226Monitor
Ursa CL-Signatures Revocation allows verifiers to generate unique identifiers for holders
MediumCVSS 6.5No exploitEPSS 0%hyperledger · ursaJan 16, 2024
- CVE-2022-3602321Monitor
Remote denial of service in Hyperledger Fabric Gateway
MediumCVSS 5.3No exploitEPSS 1%hyperledger · fabricAug 18, 2022
- CVE-2024-4524421Monitor
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
MediumCVSS 5.3Proof of conceptEPSS 1%hyperledger · fabricAug 24, 2024
- CVE-2022-3102121Monitor
Unlinkability broken in ursa when verifiers use malicious keys
MediumCVSS 5.3No exploitEPSS 0%hyperledger · ursaJan 16, 2024