{"id":"CVE-2021-43669","aliases":["GHSA-j96p-r523-8r3w"],"url":"https://o3.security/vulnerability/CVE-2021-43669","summary":"HTTP Request Smuggling in github.com/hyperledger/fabric","details":"A vulnerability has been detected in HyperLedger Fabric v1.4.0, v2.0.0, v2.0.1, v2.3.0. It can easily break down as many orderers as the attacker wants. This bug can be leveraged by constructing a message whose header is invalid to the interface Order. This bug has been admitted and fixed by the developers of Fabric.","published":"2021-11-18T16:15:09.323Z","modified":"2026-08-07T19:47:04.477906Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.01091,"percentile":0.62423,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/hyperledger/fabric","fixedVersion":"2.4.0"}],"fix":{"url":"https://github.com/hyperledger/fabric/pull/2828","label":"hyperledger/fabric#2828"},"references":[{"type":"ADVISORY","url":"https://jira.hyperledger.org/browse/FAB-18528"},{"type":"FIX","url":"https://github.com/hyperledger/fabric/pull/2828"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43669"},{"type":"PACKAGE","url":"https://github.com/hyperledger/fabric"},{"type":"WEB","url":"https://github.com/hyperledger/fabric/releases/tag/v2.4.0-beta"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T19:47:04.477906Z"}}