Vulnerabilidades en hyperledger
15 resultadosAnálisis Vexday
Hyperledger apresenta um portfólio contido de 14 vulnerabilidades, com apenas 3 críticas e nenhuma sob exploração ativa registrada, reduzindo o risco imediato. A fraqueza dominante (CWE-20, validação imprópria de entrada) sugere deficiências sistemáticas em sanitização, embora o ritmo de publicações recentes (2 em 90 dias) indique atividade controlada de divulgação. O risco permanece baixo no curto prazo, mas requer atenção continuada à validação de dados em componentes críticos.
CVE-2020-11090HIGHUncontrolled Resource Consumption in Indy NodeEPSS 2.1%CVE-2022-31121HIGHImproper Input Validation in fabric hyperledgerEPSS 2.0%CVE-2022-31020HIGHRemote code execution in Indy's NODE_UPGRADE transactionEPSS 1.7%CVE-2021-21369MEDIUMPotential DoS in Besu HTTP JSON-RPC APIEPSS 1.5%CVE-2021-41272HIGHSHL, SHR, and SAR operations trigger native exception at key values in besuEPSS 1.4%CVE-2020-11093HIGHAuthorization bypass in Hyperledger IndyEPSS 1.2%CVE-2022-31006HIGHHyperledger Indy DOS vulnerabilityEPSS 1.0%CVE-2022-36023HIGHRemote denial of service in Hyperledger Fabric GatewayEPSS 0.9%CVE-2022-36025CRITICALIncorrect Conversion between Numeric Types in Besu Ethereum ClientEPSS 0.9%CVE-2024-21669CRITICALHyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VCEPSS 0.6%CVE-2023-46132HIGHCrosslinking transaction attack in hyperledger/fabricEPSS 0.5%CVE-2022-31021LOWUnlinkability broken in ursa when verifiers use malicious keysEPSS 0.4%CVE-2026-41586CRITICALObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCEEPSS 0.4%CVE-2025-30147HIGHALTBN128_ADD, ALTBN128_MUL, ALTBN128_PAIRING precompile functions do not check if points are on curveEPSS 0.3%CVE-2026-45581MEDIUMfabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service ModeEPSS 0.1%