Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-16761

21
FAUCET Score

CVE-2019-16761 describes a vulnerability in the simpleledger slp_validate npm package, specifically versions 1.0.0 and earlier. A specially crafted Bitcoin script could lead to a discrepancy between the intended SLP consensus rules and the validation result of the affected package. This could enable an attacker to trigger a hard-fork from the SLP consensus. The vulnerability has a CVSS score of 6.1 (Medium), indicating a moderate severity. It requires high privileges and user interaction, but can be exploited over the network. The potential impact is high availability and integrity, as it could disrupt the SLP network. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness. All versions of the slp-validate package greater than 1.0.0 have been patched.

Impacted Technologies

VendorProductVersion(s)CPE
1.0.0CPE matchmatch criteria
cpe:2.3:a:simpleledger:slp-validate:1.0.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.7MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.5
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.99%
Probability of exploitation in next 30 days
EPSS Percentile
59.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0099 is in the 93rd percentile among its peer group of 4,931 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: slp-validateFixed in: 1.0.1

Vendor Advisories (1)

npmGHSA-wmx6-vxcf-c3grcritical

Validation Bypass in slp-validate

Nov 15, 2019

References

github.com / simpleledger/slp-validate/commit/50ad96c2798dad6b9f9a13333dd05232defe5730
PatchThird Party Advisory
github.com / simpleledger/slp-validate/security/advisories/GHSA-wmx6-vxcf-c3gr
PatchThird Party Advisory