CVE-2025-59942 is a high-severity vulnerability affecting go-f3 versions 0.8.6 and below, a Golang implementation of Fast Finality for Filecoin. This flaw allows an attacker to crash vulnerable Filecoin nodes by sending specially crafted "poison" messages that trigger an integer overflow during signer index validation. The attack requires direct message delivery to each target, as the messages are not self-propagating. While the CVSS score is 7.5 (High) due to its network attack vector and high availability impact, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.8.7CPE matchmatch criteria | cpe:2.3:a:filecoin:go-f3:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.