Vulnerabilidades em Hyperledger
16 resultadosAnálise Vexday
Hyperledger apresenta um footprint de risco mínimo com apenas 1 CVE registrada na base, nenhuma sob exploração ativa (KEV) e nenhuma crítica. A vulnerabilidade identificada relaciona-se a CWE-400 (Uncontrolled Resource Consumption), sem impacto imediato detectado. Não há evidência de risco recente, sendo a ameaça pouco relevante para priorização operacional.
CVE-2022-31020HIGHRemote code execution in Indy's NODE_UPGRADE transactionEPSS 2.2%CVE-2020-11090HIGHUncontrolled Resource Consumption in Indy NodeEPSS 2.1%CVE-2022-31121HIGHImproper Input Validation in fabric hyperledgerEPSS 2.0%CVE-2021-21369MEDIUMPotential DoS in Besu HTTP JSON-RPC APIEPSS 1.5%CVE-2021-41272HIGHSHL, SHR, and SAR operations trigger native exception at key values in besuEPSS 1.4%CVE-2020-11093HIGHAuthorization bypass in Hyperledger IndyEPSS 1.2%CVE-2022-31006HIGHHyperledger Indy DOS vulnerabilityEPSS 1.1%CVE-2022-36023HIGHRemote denial of service in Hyperledger Fabric GatewayEPSS 1.1%CVE-2022-36025CRITICALIncorrect Conversion between Numeric Types in Besu Ethereum ClientEPSS 1.0%CVE-2024-21669CRITICALHyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VCEPSS 0.6%CVE-2026-41586CRITICALObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCEEPSS 0.5%CVE-2023-46132HIGHCrosslinking transaction attack in hyperledger/fabricEPSS 0.5%CVE-2022-31021LOWUnlinkability broken in ursa when verifiers use malicious keysEPSS 0.4%CVE-2025-30147HIGHALTBN128_ADD, ALTBN128_MUL, ALTBN128_PAIRING precompile functions do not check if points are on curveEPSS 0.3%CVE-2026-53658MEDIUMFabric CA: LDAP Injection via Unescaped Username in GetUser FilterEPSS 0.3%CVE-2026-45581MEDIUMfabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service ModeEPSS 0.1%