DFINITY Foundation develops distributed computing infrastructure and tooling for the Internet Computer platform, including the Candid serialization format, the Motoko programming language, and canister development kits. Vulnerabilities affecting the vendor's offerings concentrate on memory-management issues, input validation, and control-flow weaknesses that recur across language runtimes and developer-facing components.
The number and severity of CVEs published that impact products developed by DFINITY Foundation over time
Of all the CVEs published by DFINITY Foundation as a CNA, 100.0% affect products that DFINITY Foundation develops as a vendor.
Of all the CVEs published that affect products developed by DFINITY Foundation, 100.0% are self-published by DFINITY Foundation as a CNA.
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1631CRITICAL Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, which will then be use | Feb 21, 2024 | 9.1 | 26 | NO | NO |
CVE-2024-7884HIGH When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the | Sep 5, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-4435HIGH When storing unbounded types in a BTreeMap, a node is represented as a linked list of "memory chunks". It was discovered recently that when we deallocate a node, in some cases only | May 21, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-6245HIGH The Candid library causes a Denial of Service while
parsing a specially crafted payload with 'empty' data type. For example,
if the payload is `record { * ; empty }` and the cani | Dec 8, 2023 | 7.5 | 21 | NO | NO |
CVE-2024-11991MEDIUM Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of write barriers in a few locations. This vulnerability could pot | Dec 9, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by DFINITY Foundation.
Media articles that mention a CVE ID that affects a product developed by DFINITY Foundation — matched by CVE ID, not by vendor name.