Hyperledger is a Linux Foundation umbrella of distributed-ledger and blockchain frameworks, with vulnerabilities concentrated in a narrow set of core projects including Fabric, Ursa, Aries Cloud Agent, and Iroha that serve as building blocks for enterprise blockchain solutions. The recurring weakness classes—improper input validation, cryptographic signature verification flaws, use of weak cryptographic algorithms, control-flow implementation errors, and authentication-bypass conditions—reflect the security-sensitive demands of consensus mechanisms, identity management, and cryptographic operations fundamental to blockchain infrastructure. Defenders should prioritize cryptographic and authentication-layer patches in this ecosystem and track disclosures within the Hyperledger community closely; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hyperledger over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-21669HIGH Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments. When verifying W3C F | Jan 11, 2024 | 8.8 | 28 | NO | NO |
CVE-2022-45196HIGH Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the same Channel name. NOTE: the official Fabri | Nov 12, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-31121HIGH Hyperledger Fabric is a permissioned distributed ledger framework. In affected versions if a consensus client sends a malformed consensus request to an orderer it may crash the ord | Jul 7, 2022 | 7.5 | 25 | NO | NO |
CVE-2018-3756HIGH Hyperledger Iroha versions v1.0_beta and v1.0.0_beta-1 are vulnerable to transaction and block signature verification bypass in the transaction and block validator allowing a singl | Jun 1, 2018 | 7.5 | 23 | NO | NO |
CVE-2024-21670HIGH Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guar | Jan 16, 2024 | 8.1 | 22 | NO | NO |
CVE-2023-46132MEDIUM Hyperledger Fabric is an open source permissioned distributed ledger framework. Combining two molecules to one another, called "cross-linking" results in a molecule with a chemical | Nov 14, 2023 | 6.5 | 20 | NO | NO |
CVE-2022-36023MEDIUM Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed req | Aug 18, 2022 | 5.3 | 20 | NO | NO |
CVE-2024-22192MEDIUM Ursa is a cryptographic library for use with blockchains. The revocation scheme that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guar | Jan 16, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-45244MEDIUM Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window. | Aug 25, 2024 | 5.3 | 17 | NO | NO |
CVE-2022-31021MEDIUM Ursa is a cryptographic library for use with blockchains. A weakness in the Hyperledger AnonCreds specification that is not mitigated in the Ursa and AnonCreds implementations is t | Jan 16, 2024 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hyperledger.
Media articles that mention a CVE ID that affects a product developed by Hyperledger — matched by CVE ID, not by vendor name.