Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-39193

20
FAUCET Score

CVE-2021-39193 describes a bug in Frontier's pallet-ethereum, affecting Substrate's Ethereum compatibility layer, where invalid transactions with oversized input data could be included in the Ethereum block state. While these transactions appear included, they are rejected by the EVM and have no impact on the internal Ethereum or Substrate state. The vulnerability carries a CVSS score of 5.3 (Medium), indicating a network-based attack with low complexity and no user interaction required. The potential impact is limited to low integrity, as it doesn't alter system state. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public awareness or concern.

Impacted Technologies

VendorProductVersion(s)CPE
< 2021-09-03CPE matchmatch criteria
cpe:2.3:a:parity:frontier:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.19%
Probability of exploitation in next 30 days
EPSS Percentile
64.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0119 is in the 43rd percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

rustGHSA-hw4v-5x4h-c3xmmedium

Transaction validity oversight in pallet-ethereum

Sep 1, 2021

References

github.com / paritytech/frontier/commit/0b962f218f0cdd796dadfe26c3f09e68f7861b26
PatchThird Party Advisory
github.com / paritytech/frontier/pull/465
PatchThird Party Advisory
github.com / paritytech/frontier/pull/465/commits/8a2b890a2fb477d5fedd0e4335b00623832849ae
PatchThird Party Advisory
github.com / paritytech/frontier/security/advisories/GHSA-hw4v-5x4h-c3xm
PatchThird Party Advisory