Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Hyperledger — Vulnerabilities & Security Advisories 15

Browse all 15 CVE security advisories affecting Hyperledger. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Hyperledger serves as an enterprise-grade blockchain framework for developing distributed ledger applications across supply chain, finance, and healthcare sectors. Historically, common vulnerabilities include remote code execution, cross-site scripting, and privilege escalation, often stemming from misconfigurations or insecure API implementations. The platform's modular architecture allows for granular security controls, though past incidents have exposed flaws in consensus mechanisms and smart contract vulnerabilities. With 14 CVEs documented, most issues receive patches within reasonable timeframes, though some critical flaws have demonstrated potential for network compromise when combined with other weaknesses. The framework's permissioned nature inherently reduces certain attack surfaces compared to public blockchains.

CVE ID Title CVSS Severity Published
CVE-2026-45581 fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode — fabric-chaincode-java CWE-532 5.5 Medium 2026-06-08
CVE-2026-41586 ObjectInputStream.readObject() without ObjectInputFilter in fabric-sdk-java allows Java deserialization RCE — fabric CWE-502 8.8AI High AI 2026-05-07
CVE-2025-30147 ALTBN128_ADD, ALTBN128_MUL, ALTBN128_PAIRING precompile functions do not check if points are on curve — besu-native CWE-325 7.5AI High AI 2025-05-07
CVE-2022-31021 Unlinkability broken in ursa when verifiers use malicious keys — ursa CWE-829 3.3 Low 2024-01-16
CVE-2024-21669 Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC — aries-cloudagent-python CWE-347 9.9 Critical 2024-01-11
CVE-2023-46132 Crosslinking transaction attack in hyperledger/fabric — fabric CWE-362 7.1 High 2023-11-14
CVE-2022-36025 Incorrect Conversion between Numeric Types in Besu Ethereum Client — besu CWE-681 9.1 Critical 2022-09-24
CVE-2022-31006 Hyperledger Indy DOS vulnerability — indy-node CWE-400 7.5 High 2022-09-09
CVE-2022-31020 Remote code execution in Indy's NODE_UPGRADE transaction — indy-node CWE-287 8.8 High 2022-09-06
CVE-2022-36023 Remote denial of service in Hyperledger Fabric Gateway — fabric CWE-20 7.0 High 2022-08-18
CVE-2022-31121 Improper Input Validation in fabric hyperledger — fabric CWE-20 7.5 High 2022-07-07
CVE-2021-41272 SHL, SHR, and SAR operations trigger native exception at key values in besu — besu CWE-681 7.5 High 2021-12-13
CVE-2021-21369 Potential DoS in Besu HTTP JSON-RPC API — besu CWE-400 6.5 Medium 2021-03-09
CVE-2020-11093 Authorization bypass in Hyperledger Indy — indy-node CWE-347 7.5 High 2020-12-24
CVE-2020-11090 Uncontrolled Resource Consumption in Indy Node — Indy Node CWE-400 7.5 High 2020-06-11

This page lists every published CVE security advisory associated with Hyperledger. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.