Fabric
Hyperledger · 6 CVEs
CVE-2026-41586
CRITICAL
ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCE
May 7, 2026
CVE-2024-45244
MEDIUM
Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expect…
Aug 25, 2024
CVE-2023-46132
HIGH
Crosslinking transaction attack in hyperledger/fabric
Nov 14, 2023
CVE-2022-45196
HIGH
Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted ch…
Nov 12, 2022
CVE-2022-36023
HIGH
Remote denial of service in Hyperledger Fabric Gateway
Aug 18, 2022
CVE-2022-31121
HIGH
Improper Input Validation in fabric hyperledger
Jul 7, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-41586 | ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCE | CRITICAL | 0.63% | May 7, 2026 |
| CVE-2024-45244 | Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window. | MEDIUM | 0.59% | Aug 25, 2024 |
| CVE-2023-46132 | Crosslinking transaction attack in hyperledger/fabric | HIGH | 0.52% | Nov 14, 2023 |
| CVE-2022-45196 | Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted channel tx with the same Channel name. NOT… | HIGH | 0.85% | Nov 12, 2022 |
| CVE-2022-36023 | Remote denial of service in Hyperledger Fabric Gateway | HIGH | 1.10% | Aug 18, 2022 |
| CVE-2022-31121 | Improper Input Validation in fabric hyperledger | HIGH | 2.09% | Jul 7, 2022 |
Showing 1 to 6 of 6 CVEs