{"id":"CVE-2022-31121","aliases":["BIT-hyperledger-fabric-orderer-2022-31121","BIT-hyperledger-fabric-peer-2022-31121","BIT-hyperledger-fabric-tools-2022-31121","GHSA-72x4-cq6r-jp4p"],"url":"https://o3.security/vulnerability/CVE-2022-31121","summary":"Improper Input Validation in fabric hyperledger","details":"### Impact\nIf a consensus client sends a malformed consensus request to an orderer it may crash the orderer node.\nThis fix checks for the malformed consensus request and returns an error to the consensus client.\n\n### Specific Go Packages Affected\ngithub.com/hyperledger/fabric/orderer/common/cluster\n\n### Patches\nFixed in v2.2.7 and v2.4.5.\n\n### Workarounds\nNone, users must upgrade to v2.2.7 or v2.4.5.\n\n### References\nhttps://github.com/hyperledger/fabric/releases/tag/v2.2.7\nhttps://github.com/hyperledger/fabric/releases/tag/v2.4.5\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [Hyperledger Fabric repository](https://github.com/hyperledger/fabric/issues)\n\n### Credits\nThank you to Haosheng Wang of OPPO ZIWU Security Lab for this disclosure.","published":"2022-07-07T18:00:14Z","modified":"2026-08-12T03:51:44.739005738Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.01983,"percentile":0.79032,"asOf":"2026-08-25"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/hyperledger/fabric","fixedVersion":"2.2.7"},{"ecosystem":"Go","name":"github.com/hyperledger/fabric","fixedVersion":"2.4.5"}],"fix":{"url":"https://github.com/hyperledger/fabric/commit/0f18359493bcbd5f9f9d1a9b05adabfe5da23b06","label":"hyperledger/fabric@0f18359"},"references":[{"type":"WEB","url":"https://github.com/hyperledger/fabric/releases/tag/v2.2.7"},{"type":"WEB","url":"https://github.com/hyperledger/fabric/releases/tag/v2.4.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31121.json"},{"type":"ADVISORY","url":"https://github.com/hyperledger/fabric/security/advisories/GHSA-72x4-cq6r-jp4p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31121"},{"type":"FIX","url":"https://github.com/hyperledger/fabric/commit/0f18359493bcbd5f9f9d1a9b05adabfe5da23b06"},{"type":"PACKAGE","url":"https://github.com/hyperledger/fabric"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:44.739005738Z"}}