OVERVIEW CVE-2026-40069 affects the BSV Ruby SDK versions 0.1.0 through 0.8.1, a blockchain development library for the BSV network. The vulnerability exists in the ARC (Merkle Network's transaction status API) failure detection mechanism, which fails to properly recognize multiple transaction rejection statuses. Specifically, the SDK treats responses indicating INVALID, MALFORMED, MINED_IN_STALE_BLOCK, and ORPHAN transactions as successful broadcasts, when they should be flagged as failures. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no privileges or user interaction. The primary impact is integrity compromise, as applications relying on the SDK's broadcast success confirmation may incorrectly trust transactions that were never accepted by the network. This creates downstream operational risk where transaction-dependent actions are executed based on false assumptions about blockchain acceptance. EXPLOITATION STATUS There is no indication of active exploitation, with the vulnerability absent from CISA's Known Exploited Vulnerabilities catalog and classified as inactive on vulnerability tracking platforms. The EPSS score of 0.00041 suggests minimal real-world exploitation probability currently. The vulnerability was remediated in version 0.8.2, and community awareness appears limited given the specialized nature of blockchain SDK usage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.0, < 0.8.2CPE matchmatch criteria | cpe:2.3:a:sgbett:bsv_ruby_sdk:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.