Parity develops cryptocurrency and blockchain infrastructure software, including Ethereum client implementations, smart-contract languages, and cryptographic libraries that sit at the foundation of decentralized systems. Its vulnerability profile centers on parser, arithmetic, and resource-management weaknesses—such as improper input validation, incorrect calculation, resource exhaustion, and control-flow errors—that recur across its client and compiler products and reflect the precision demands of financial and consensus-critical code. A moderate share of its disclosures reach serious severity and acquire public exploit code; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Parity over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38195CRITICAL An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it allows the R or S parameter to be larger than the curve order | Aug 8, 2021 | 9.8 | 31 | NO | NO |
CVE-2017-18016MEDIUM Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy en | Jan 11, 2018 | 5.3 | 31 | NO | YES |
CVE-2017-14460HIGH An exploitable overly permissive cross-domain (CORS) whitelist vulnerability exists in JSON-RPC of Parity Ethereum client version 1.7.8. An automatically sent JSON object to JSON-R | Jan 19, 2018 | 7.5 | 24 | NO | NO |
CVE-2023-28431HIGH Frontier is an Ethereum compatibility layer for Substrate. Frontier's `modexp` precompile uses `num-bigint` crate under the hood. In the implementation prior to pull request 1017, | Mar 22, 2023 | 7.5 | 23 | NO | NO |
CVE-2022-36008MEDIUM Frontier is Substrate's Ethereum compatibility layer. A security issue was discovered affecting parsing of the RPC result of the exit reason in case of EVM reversion. In release bu | Aug 19, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-21685MEDIUM Frontier is Substrate's Ethereum compatibility layer. Prior to commit number `8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664`, a bug in Frontier's MODEXP precompile implementation can ca | Jan 14, 2022 | 6.5 | 23 | NO | NO |
CVE-2019-25003HIGH An issue was discovered in the libsecp256k1 crate before 0.3.1 for Rust. Scalar::check_overflow allows a timing side-channel attack; consequently, attackers can obtain sensitive in | Dec 31, 2020 | 7.5 | 23 | NO | NO |
CVE-2023-45130HIGH Frontier is Substrate's Ethereum compatibility layer. Prior to commit aea528198b3b226e0d20cce878551fd4c0e3d5d0, at the end of a contract execution, when opcode SUICIDE marks a cont | Oct 13, 2023 | 7.5 | 21 | NO | NO |
CVE-2022-39242MEDIUM Frontier is an Ethereum compatibility layer for Substrate. Prior to commit d3beddc6911a559a3ecc9b3f08e153dbe37a8658, the worst case weight was always accounted as the block weight | Sep 24, 2022 | 5.3 | 20 | NO | NO |
CVE-2022-31111MEDIUM Frontier is Substrate's Ethereum compatibility layer. In affected versions the truncation done when converting between EVM balance type and Substrate balance type was incorrectly i | Jul 6, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Parity.
Media articles that mention a CVE ID that affects a product developed by Parity — matched by CVE ID, not by vendor name.