Skip to main content

Security Advisories

The following security advisories are related to the Internet Computer Protocol.

CVEBrief descriptionReferenceAffected productsAffected versionsCVSS 3.1Issued on
CVE-2023-6245Candid infinite decoding loop through specially crafted payloadAdvisorycandid (Rust)>= 0.9.0, < 0.9.10High (7.5/10)Dec 8, 2023
CVE-2024-1631agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate`Advisory@dfinity/auth-client (npm) @dfinity/identity (npm)>= 0.20.0-beta.0, < 1.0.1Critical (9.1/10)Feb 21, 2024
CVE-2024-4435Stable BTreeMap memory leak when deallocating nodes with overflowsAdvisoryic-stable-structures (Rust)>= 0.6.0, < 0.6.4Medium (5.9/10)May 21, 2024