Chainsafe develops blockchain and distributed-systems libraries, including Ethermint, Lodestar, and JavaScript implementations of libp2p networking protocols that serve as critical infrastructure in decentralized applications and consensus networks. Its vulnerability footprint concentrates on cryptographic validation, authentication mechanisms, and integer handling within these components, reflecting the mathematical rigor and protocol-state complexity demanded by distributed-ledger and peer-to-peer environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chainsafe over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29219HIGH Lodestar is a TypeScript implementation of the Ethereum Consensus specification. Prior to version 0.36.0, there is a possible consensus split given maliciously-crafted `AttesterSla | May 24, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-24759HIGH `@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `@chainsafe/libp2p-noise` before 4.1.2 and 5.0.3 does not cor | Mar 17, 2022 | 7.4 | 24 | NO | NO |
CVE-2021-25837HIGH Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. Due to the inconsistency between the Storage caching cycle and the Tx processing | Feb 8, 2021 | 7.5 | 23 | NO | NO |
CVE-2021-25836HIGH Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. The bytecode set in a FAILED transaction wrongfully remains in memory(stateObject | Feb 8, 2021 | 7.5 | 22 | NO | NO |
CVE-2021-25835HIGH Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Since ethermint uses the same chainIDEpoch and signature schemes | Feb 8, 2021 | 7.5 | 22 | NO | NO |
CVE-2021-25834HIGH Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim sends a very large nonce transaction, the attacker can replay | Feb 8, 2021 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chainsafe.
Media articles that mention a CVE ID that affects a product developed by Chainsafe — matched by CVE ID, not by vendor name.