stellar records
7 published records for vendor stellar.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-190 Integer Overflow or Wraparound1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-248 Uncaught Exception1
- CWE-287 Improper Authentication1
- CWE-670 Always-Incorrect Control Flow Implementation1
- CWE-697 Incorrect Comparison1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2023-46135No exploit | Panic in SignedPayload::from_payloadstellar · rs-stellar-strkey · CWE-248 | High7.5 | — | 0.8% | Oct 25, 2023 |
30Monitor | CVE-2026-26267No exploit | rs-soroban-sdk #[contractimpl] macro calls inherent function instead of trait function when names collidestellar · rs-soroban-sdk · CWE-670 | High7.5 | — | 0.5% | Feb 19, 2026 |
30Monitor | CVE-2026-29795No exploit | stellar-xdr: `StringM::from_str` bypasses max length validationstellar · stellar-xdr · CWE-770 | High7.5 | — | 0.3% | Mar 6, 2026 |
26Monitor | CVE-2023-40580No exploit | Freighter mnemonic phrase may be accessed by Javascript through a private APIstellar · freighter · CWE-200 | Medium6.5 | — | 0.7% | Aug 25, 2023 |
26Monitor | CVE-2021-32738No exploit | Utils.readChallengeTx does not verify the server account signaturestellar · js-stellar-sdk · CWE-287 | Medium6.5 | — | 0.5% | Jul 2, 2021 |
21Monitor | CVE-2026-24889No exploit | soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64stellar · rs-soroban-sdk · CWE-190 | Medium5.3 | — | 0.4% | Jan 28, 2026 |
21Monitor | CVE-2026-32322No exploit | soroban-sdk: `Fr` scalar field equality comparison bypasses modular reductionstellar · rs-soroban-sdk · CWE-697 | Medium5.3 | — | 0.3% | Mar 13, 2026 |
- CVE-2023-4613530Monitor
Panic in SignedPayload::from_payload
HighCVSS 7.5No exploitEPSS 1%stellar · rs-stellar-strkeyOct 25, 2023
- CVE-2026-2626730Monitor
rs-soroban-sdk #[contractimpl] macro calls inherent function instead of trait function when names collide
HighCVSS 7.5No exploitEPSS 1%stellar · rs-soroban-sdkFeb 19, 2026
- CVE-2026-2979530Monitor
stellar-xdr: `StringM::from_str` bypasses max length validation
HighCVSS 7.5No exploitEPSS 0%stellar · stellar-xdrMar 6, 2026
- CVE-2023-4058026Monitor
Freighter mnemonic phrase may be accessed by Javascript through a private API
MediumCVSS 6.5No exploitEPSS 1%stellar · freighterAug 25, 2023
- CVE-2021-3273826Monitor
Utils.readChallengeTx does not verify the server account signature
MediumCVSS 6.5No exploitEPSS 1%stellar · js-stellar-sdkJul 2, 2021
- CVE-2026-2488921Monitor
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
MediumCVSS 5.3No exploitEPSS 0%stellar · rs-soroban-sdkJan 28, 2026
- CVE-2026-3232221Monitor
soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
MediumCVSS 5.3No exploitEPSS 0%stellar · rs-soroban-sdkMar 13, 2026