Hedera operates a distributed ledger platform and maintains the Guardian product for verifying and managing environmental and sustainability claims, a specialized enterprise role in the blockchain and compliance space. Its observed vulnerability profile centers on configuration and authentication gaps—resource exposure to unintended actors and missing authentication mechanisms for sensitive functions—characteristic of platforms managing distributed access and privileged operations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hedera over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39911HIGH Hashgraph Guardian through version 3.5.1, fixed in commit 45fbe2f, contains an unsandboxed JavaScript execution vulnerability in the Custom Logic policy block worker that allows au | Apr 9, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-45248MEDIUM Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthenticated attackers to retrieve se | May 14, 2026 | 5.3 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hedera.
Media articles that mention a CVE ID that affects a product developed by Hedera — matched by CVE ID, not by vendor name.