IOHK maintains a narrowly scoped portfolio centered on Hydra, a cryptocurrency payment and scaling protocol, with disclosed vulnerabilities centered on input-validation and cryptographic-signature-verification weaknesses that are characteristic of protocol-layer implementations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iohk over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38701CRITICAL Hydra is the layer-two scalability solution for Cardano. Users of the Hydra head protocol send the UTxOs they wish to commit into the Hydra head first to the `commit` validator, wh | Oct 4, 2023 | 9.1 | 26 | NO | NO |
CVE-2023-42449HIGH Hydra is the two-layer scalability solution for Cardano. Prior to version 0.13.0, it is possible for a malicious head initializer to extract one or more PTs for the head they are i | Oct 4, 2023 | 8.1 | 23 | NO | NO |
CVE-2023-42448HIGH Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the contestation period in the datum of the UTxO at the head validat | Oct 4, 2023 | 8.1 | 23 | NO | NO |
CVE-2023-42806MEDIUM Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\mathsf{cid}$` allows an attacker (which must be a participant of this | Sep 21, 2023 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iohk.
Media articles that mention a CVE ID that affects a product developed by Iohk — matched by CVE ID, not by vendor name.