Vulnerabilities
Vulnerable Software
Hyperledger:  >> Fabric  >> 2.2.14  Security Vulnerabilities
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays without configuring an ObjectInputFilter. This is a classic Java deserialization RCE pattern. At time of publication, there are no publicly available patches.
CVSS Score
9.3
EPSS Score
0.005
Published
2026-05-07
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.
CVSS Score
5.3
EPSS Score
0.006
Published
2024-08-25
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version 2.4.6 checks for the malformed gateway request and returns an error to the gateway client. There are no known workarounds, users must upgrade to version 2.4.6.
CVSS Score
7.0
EPSS Score
0.011
Published
2022-08-18


Contact Us

Shodan ® - All rights reserved