Stellar maintains a modestly represented vulnerability footprint centered on blockchain and distributed-ledger infrastructure, with disclosures clustering around its Soroban smart-contract SDK, JavaScript and Rust implementations, and Freighter wallet product. The recurring weakness classes reflect the software's role in cryptographic operations and user-facing authentication: resource-allocation controls, information exposure, and authentication mechanisms recur across these developer-facing and end-user tools. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stellar over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29795HIGH stellar-xdr is a library and CLI containing types and functionality for working with Stellar XDR. Prior to version 25.0.1, StringM::from_str does not validate that the input length | Mar 6, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-26267HIGH soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` macro contains a bug in how it wires up function calls. `#[con | Feb 19, 2026 | 7.5 | 24 | NO | NO |
CVE-2023-46135HIGH rs-stellar-strkey is a Rust lib for encode/decode of Stellar Strkeys. A panic vulnerability occurs when a specially crafted payload is used.`inner_payload_len` should not above 64. | Oct 25, 2023 | 7.5 | 22 | NO | NO |
CVE-2021-32738MEDIUM js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar Web Authentication states in its | Jul 2, 2021 | 6.5 | 21 | NO | NO |
CVE-2026-24889MEDIUM soroban-sdk is a Rust SDK for Soroban contracts. Arithmetic overflow can be triggered in the `Bytes::slice`, `Vec::slice`, and `Prng::gen_range` (for `u64`) methods in the `soroban | Jan 28, 2026 | 5.3 | 20 | NO | NO |
CVE-2023-40580MEDIUM Freighter is a Stellar chrome extension. It may be possible for a malicious website to access the recovery mnemonic phrase when the Freighter wallet is unlocked. This vulnerability | Aug 25, 2023 | 6.5 | 20 | NO | NO |
CVE-2026-32322MEDIUM soroban-sdk is a Rust SDK for Soroban contracts. Prior to 22.0.11, 23.5.3, and 25.3.0, The Fr (scalar field) types for BN254 and BLS12-381 in soroban-sdk compared values using thei | Mar 13, 2026 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stellar.
Media articles that mention a CVE ID that affects a product developed by Stellar — matched by CVE ID, not by vendor name.