OVERVIEW: CVE-2026-40070 affects BSV Ruby SDK versions 0.3.1 through 0.8.1. The vulnerability exists in the acquire_certificate function, which fails to validate certifier signatures before persisting certificate records to storage. Attackers can exploit both the direct acquisition protocol (by supplying forged certificate fields) and the issuance protocol (by controlling or compromising a certifier endpoint) to create fraudulent identity certificates that appear legitimate to the system. SEVERITY: The vulnerability carries a CVSS 3.1 score of 8.1 (HIGH) with a network attack vector, low complexity, and no privilege escalation required, though it does require low-level user authentication. The impact is substantial, with high confidentiality and integrity compromises possible as attackers can forge identity certificates that grant unauthorized access or impersonation capabilities. The flaw requires no user interaction and affects the system's core certificate validation mechanism. EXPLOITATION STATUS: Currently, there is no evidence of active exploitation, with an EPSS score of 0.0001 indicating minimal real-world exploitation probability. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog, and community attention remains low. Organizations should still prioritize patching to version 0.8.2 or later due to the high severity rating and the fundamental nature of the certificate validation flaw, particularly if the BSV SDK is used in authentication or identity verification workflows.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.2, < 0.3.4CPE matchmatch criteria | cpe:2.3:a:sgbett:bsv-wallet:*:*:*:*:*:ruby:*:* | ||
>= 0.3.1, < 0.8.2CPE matchmatch criteria | cpe:2.3:a:sgbett:bsv_ruby_sdk:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.