soroban-sdk
crates.io2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting soroban-sdkpage 1 of 1
- CVE-2026-24889MEDIUMCVSS 5.3EG 5.3✓ Fixed in 22.0.92026-01-28
soroban-sdk is a Rust SDK for Soroban contracts. Arithmetic overflow can be triggered in the `Bytes::slice`, `Vec::slice`, and `Prng::gen_range` (for `u64`) methods in the `soroban-sdk` in versions up to and including `25.0.1`, `23.5.1`, a…
- CVE-2026-32322MEDIUMCVSS 5.3EG 5.3✓ Fixed in 22.0.112026-03-13
soroban-sdk is a Rust SDK for Soroban contracts. Prior to 22.0.11, 23.5.3, and 25.3.0, The Fr (scalar field) types for BN254 and BLS12-381 in soroban-sdk compared values using their raw U256 representation without first reducing modulo the…
Check whether soroban-sdk is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for soroban-sdk CVEs against the assets you own.
Start Free Scan →