<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:46:34 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-160767</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-160767</link>
      <description>EUVD-2026-160767</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-160767</guid>
    </item>
    <item>
      <title>fkie_cve-2023-46132</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-46132</link>
      <description>&lt;p&gt;Hyperledger Fabric is an open source permissioned distributed ledger framework. Combining two molecules to one another, called &amp;#34;cross-linking&amp;#34; results in a molecule with a chemical formula that is composed of all atoms of the original two molecules. In Fabric, one can take a block of transactions and cross-link the transactions in a way that alters the way the peers parse the transactions. If a first peer receives a block B and a second peer receives a block identical to B but with the transactions being cross-linked, the second peer will parse transactions in a different way and thus its world state will deviate from the first peer. Orderers or peers cannot detect that a block has its transactions cross-linked, because there is a vulnerability in the way Fabric hashes the transactions of blocks. It simply and naively concatenates them, which is insecure and lets an adversary craft a &amp;#34;cross-linked block&amp;#34; (block with cross-linked transactions) which alters the way peers process transactions. For example, it is possible to select a transaction and manipulate a peer to completely avoid processing it, without changing the computed hash of the block. Additional validations have been added in v2.2.14 and v2.5.5 to detect potential cross-linking issues before processing blocks. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hyperledger Fabric is an open source permissioned distributed ledger framework. Combining two molecules to one another, called &amp;#34;cross-linking&amp;#34; results in a molecule with a chemical formula that is composed of all atoms of the original two molecules. In Fabric, one can take a block of transactions and cross-link the transactions in a way that alters the way the peers parse the transactions. If a first peer receives a block B and a second peer receives a block identical to B but with the transactions being cross-linked, the second peer will parse transactions in a different way and thus its world state will deviate from the first peer. Orderers or peers cannot detect that a block has its transactions cross-linked, because there is a vulnerability in the way Fabric hashes the transactions of blocks. It simply and naively concatenates them, which is insecure and lets an adversary craft a &amp;#34;cross-linked block&amp;#34; (block with cross-linked transactions) which alters the way peers process transactions. For example, it is possible to select a transaction and manipulate a peer to completely avoid processing it, without changing the computed hash of the block. Additional validations have been added in v2.2.14 and v2.5.5 to detect potential cross-linking issues before processing blocks. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-46132</guid>
    </item>
    <item>
      <title>GHSA-v9w2-543f-h69m — Fabric vulnerable to crosslinking transaction attack</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v9w2-543f-h69m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/hyperledger/fabric&lt;/p&gt;
&lt;p&gt;# Short summary&lt;/p&gt;
&lt;p&gt;Combining two molecules to one another, called &amp;#34;cross-linking&amp;#34; results in a molecule with a chemical formula that is composed of all atoms of the original two molecules.&lt;/p&gt;
&lt;p&gt;In Fabric, one can take a block of transactions and cross-link the transactions in a way that alters the way the peers parse the transactions. If a first peer receives a block `B` and a second peer receives a block identical to `B` but with the transactions being cross-linked, the second peer will parse transactions in a different way and thus its world state will deviate from the first peer.&lt;/p&gt;
&lt;p&gt;Orderers or peers cannot detect that a block has its transactions cross-linked, because there is a vulnerability in the way Fabric hashes the transactions of blocks. It simply and naively concatenates them, which is insecure and lets an adversary craft a &amp;#34;cross-linked block&amp;#34; (block with cross-linked transactions) which alters the way peers process transactions. 
For example, it is possible to select a transaction and manipulate a peer to completely avoid processing it, without changing the computed hash of the block.&lt;/p&gt;
&lt;p&gt;Additional validations have been added in v2.2.14 and v2.5.5 to detect potential cross-linking issues before processing blocks.&lt;/p&gt;
&lt;p&gt;## Impact
In V1 and V2, we only have a crash fault tolerant orderer and as such, the security model Fabric operates in is that the orderer is honest,
but peers may be malicious. As such, a peer that replicates a block from a malicious peer can have a state fo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/hyperledger/fabric&lt;/p&gt;
&lt;p&gt;# Short summary&lt;/p&gt;
&lt;p&gt;Combining two molecules to one another, called &amp;#34;cross-linking&amp;#34; results in a molecule with a chemical formula that is composed of all atoms of the original two molecules.&lt;/p&gt;
&lt;p&gt;In Fabric, one can take a block of transactions and cross-link the transactions in a way that alters the way the peers parse the transactions. If a first peer receives a block `B` and a second peer receives a block identical to `B` but with the transactions being cross-linked, the second peer will parse transactions in a different way and thus its world state will deviate from the first peer.&lt;/p&gt;
&lt;p&gt;Orderers or peers cannot detect that a block has its transactions cross-linked, because there is a vulnerability in the way Fabric hashes the transactions of blocks. It simply and naively concatenates them, which is insecure and lets an adversary craft a &amp;#34;cross-linked block&amp;#34; (block with cross-linked transactions) which alters the way peers process transactions. 
For example, it is possible to select a transaction and manipulate a peer to completely avoid processing it, without changing the computed hash of the block.&lt;/p&gt;
&lt;p&gt;Additional validations have been added in v2.2.14 and v2.5.5 to detect potential cross-linking issues before processing blocks.&lt;/p&gt;
&lt;p&gt;## Impact
In V1 and V2, we only have a crash fault tolerant orderer and as such, the security model Fabric operates in is that the orderer is honest,
but peers may be malicious. As such, a peer that replicates a block from a malicious peer can have a state fo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v9w2-543f-h69m</guid>
    </item>
    <item>
      <title>gsd-2023-46132</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-46132</link>
      <description>gsd-2023-46132</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-46132</guid>
    </item>
  </channel>
</rss>
