Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hedera

First CVE: Apr 9, 2026Active for: 1 yearTotal CVEs: 2

Hedera operates a distributed ledger platform and maintains the Guardian product for verifying and managing environmental and sustainability claims, a specialized enterprise role in the blockchain and compliance space. Its observed vulnerability profile centers on configuration and authentication gaps—resource exposure to unintended actors and missing authentication mechanisms for sensitive functions—characteristic of platforms managing distributed access and privileged operations. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
2
Total CVEs
More Total CVEs than 56% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hedera over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2026
3 months ago
Most Recent CVE
May 14, 2026
72 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (2 CVEs).

2 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-39911HIGH
Hashgraph Guardian through version 3.5.1, fixed in commit 45fbe2f, contains an unsandboxed JavaScript execution vulnerability in the Custom Logic policy block worker that allows au
Apr 9, 20268.832NONO
CVE-2026-45248MEDIUM
Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthenticated attackers to retrieve se
May 14, 20265.326NONO
View all 2 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products2 CVEs
50%
50%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (50.0%)
High0 (0.0%)
None1 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (2 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hedera.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hedera — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hedera's Products

View all 1 CNAs →

Top CWEs