VendorsIohkhydraany version
Vulnerabilities

Iohk Input Output (IOHK) Hydra any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-38701
Hydra's committed UTxOs at Commit validator and UTxOs at Initial validator can be spent arbitrarily by anyone
Published 2023-10-04 · Modified
9.1EPSS 0.009
CVE-2023-42449
Malicious head initialiser can extract PTs from control of Hydra scripts, leading to locked participant commits or spoofed commits
Published 2023-10-04 · Modified
8.1EPSS 0.009
CVE-2023-42448
Hydra's contestation period in head datum can be modified during Close transaction, allowing malicious participant to freely modify the contestation deadline
Published 2023-10-04 · Modified
8.1EPSS 0.008
CVE-2023-42806
Snapshot signature not including HeadID will allow replay attacks
Published 2023-09-21 · Modified
6.5EPSS 0.005