Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hyperledger

First CVE: Jun 1, 2018Active for: 8 yearsTotal CVEs: 10
21.9
VTI Score
Low

Hyperledger is a Linux Foundation umbrella of distributed-ledger and blockchain frameworks, with vulnerabilities concentrated in a narrow set of core projects including Fabric, Ursa, Aries Cloud Agent, and Iroha that serve as building blocks for enterprise blockchain solutions. The recurring weakness classes—improper input validation, cryptographic signature verification flaws, use of weak cryptographic algorithms, control-flow implementation errors, and authentication-bypass conditions—reflect the security-sensitive demands of consensus mechanisms, identity management, and cryptographic operations fundamental to blockchain infrastructure. Defenders should prioritize cryptographic and authentication-layer patches in this ecosystem and track disclosures within the Hyperledger community closely; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hyperledger over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 1, 2018
8 years ago
Most Recent CVE
Aug 25, 2024
698 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-21669HIGH
Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments. When verifying W3C F
Jan 11, 20248.828NONO
CVE-2022-45196HIGH
Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the same Channel name. NOTE: the official Fabri
Nov 12, 20227.525NONO
CVE-2022-31121HIGH
Hyperledger Fabric is a permissioned distributed ledger framework. In affected versions if a consensus client sends a malformed consensus request to an orderer it may crash the ord
Jul 7, 20227.525NONO
CVE-2018-3756HIGH
Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transaction and block validator allowing a singl
Jun 1, 20187.523NONO
CVE-2024-21670HIGH
Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guar
Jan 16, 20248.122NONO
CVE-2023-46132MEDIUM
Hyperledger Fabric is an open source permissioned distributed ledger framework. Combining two molecules to one another, called "cross-linking" results in a molecule with a chemical
Nov 14, 20236.520NONO
CVE-2022-36023MEDIUM
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed req
Aug 18, 20225.320NONO
CVE-2024-22192MEDIUM
Ursa is a cryptographic library for use with blockchains. The revocation scheme that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guar
Jan 16, 20246.519NONO
CVE-2024-45244MEDIUM
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
Aug 25, 20245.317NONO
CVE-2022-31021MEDIUM
Ursa is a cryptographic library for use with blockchains. A weakness in the Hyperledger AnonCreds specification that is not mitigated in the Ursa and AnonCreds implementations is t
Jan 16, 20245.315NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low2 (20.0%)
High0 (0.0%)
None8 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hyperledger.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hyperledger — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hyperledger's Products

View all 3 CNAs →

Top CWEs