FISCO BCOS is a permissioned blockchain platform developed for enterprise and financial use cases, with a narrow but strategically important product footprint. Vulnerabilities in the platform have emerged at a modest volume and reflect the attack surface typical of distributed-ledger systems; defenders should monitor this vendor's security advisories given its role in mission-critical financial infrastructure. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fisco Bcos over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28937HIGH FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an invalid header, will cause normal nodes to stop producing ne | May 15, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-28936HIGH FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow and cause a Denial of Service (DoS) via an unusually large vi | May 15, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-26534HIGH FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via a malicious viewchange packet, will cause normal nodes to change view excessively and st | Mar 17, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-46359HIGH FISCO-BCOS release-3.0.0-rc2 contains a denial of service vulnerability. Some transactions may not be committed successfully, and malicious users may use this to achieve double-spe | Feb 7, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-35041HIGH The blockchain node in FISCO-BCOS V2.7.2 may have a bug when dealing with unformatted packet and lead to a crash. A malicious node can send a packet continuously. The packet is in | Jun 24, 2021 | 7.5 | 23 | NO | NO |
FISCO BCOS 3.11.0 has an issue with synchronization of the transaction pool that can, for example, be observed when a malicious node (that has modified the codebase to allow a larg | Apr 6, 2025 | 3.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fisco Bcos.
Media articles that mention a CVE ID that affects a product developed by Fisco Bcos — matched by CVE ID, not by vendor name.