{"id":"CVE-2019-16761","aliases":["GHSA-wmx6-vxcf-c3gr"],"url":"https://o3.security/vulnerability/CVE-2019-16761","summary":"Validation Bypass in slp-validate","details":"A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slp-validate@1.0.0 npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. All versions >1.0.0 have been patched.","published":"2019-11-15T23:15:11.317Z","modified":"2026-07-09T02:49:17.181943Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"slp-validate","fixedVersion":"1.0.1"}],"fix":{"url":"https://github.com/simpleledger/slp-validate/commit/50ad96c2798dad6b9f9a13333dd05232defe5730#diff-fe58606994c412ba56a65141a7aa4a62L123","label":"simpleledger/slp-validate@50ad96c"},"references":[{"type":"FIX","url":"https://github.com/simpleledger/slp-validate/commit/50ad96c2798dad6b9f9a13333dd05232defe5730#diff-fe58606994c412ba56a65141a7aa4a62L123"},{"type":"FIX","url":"https://github.com/simpleledger/slp-validate/security/advisories/GHSA-wmx6-vxcf-c3gr"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T02:49:17.181943Z"}}