github.com/hyperledger/fabric
Go6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/hyperledger/fabricpage 1 of 1
- CVE-2021-43667HIGHCVSS 7.5EG 7.5fixed in 2.3.3 or 2.2.4, by version range2021-11-18
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.1.0. This bug can be leveraged by constructing a message whose payload is nil and sending this message with the method 'forwardToLeader'. This bug has been admitted…
- CVE-2021-43669HIGHCVSS 7.5EG 7.5fixed in 2.4.02021-11-18
A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0. It can easily break down as many orderers as the attacker wants. This bug can be leveraged by constructing a message whose header is invalid to the int…
- CVE-2022-31121HIGHCVSS 7.5EG 7.5fixed in 2.2.7 or 2.4.5, by version range2022-07-07
Hyperledger Fabric is a permissioned distributed ledger framework. In affected versions if a consensus client sends a malformed consensus request to an orderer it may crash the orderer node. A fix has been added in commit 0f1835949 which c…
- CVE-2022-36023HIGHCVSS 7.0EG 7.0fixed in 2.4.62022-08-18
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version …
- CVE-2023-46132MEDIUMCVSS 6.5EG 6.5fixed in 2.2.14 or 2.5.5, by version range2023-11-14
Hyperledger Fabric is an open source permissioned distributed ledger framework. Combining two molecules to one another, called "cross-linking" results in a molecule with a chemical formula that is composed of all atoms of the original two …
- CVE-2024-45244MEDIUMCVSS 5.3EG 5.42024-08-25
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
Check whether github.com/hyperledger/fabric is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/hyperledger/fabric CVEs against the assets you own.
Book a Demo →