{"id":"CVE-2023-46132","aliases":["BIT-hyperledger-fabric-orderer-2023-46132","BIT-hyperledger-fabric-peer-2023-46132","BIT-hyperledger-fabric-tools-2023-46132","GHSA-v9w2-543f-h69m"],"url":"https://o3.security/vulnerability/CVE-2023-46132","summary":"Crosslinking transaction attack in hyperledger/fabric","details":"Hyperledger Fabric is an open source permissioned distributed ledger framework. Combining two molecules to one another, called \"cross-linking\" results in a molecule with a chemical formula that is composed of all atoms of the original two molecules. In Fabric, one can take a block of transactions and cross-link the transactions in a way that alters the way the peers parse the transactions. If a first peer receives a block B and a second peer receives a block identical to B but with the transactions being cross-linked, the second peer will parse transactions in a different way and thus its world state will deviate from the first peer. Orderers or peers cannot detect that a block has its transactions cross-linked, because there is a vulnerability in the way Fabric hashes the transactions of blocks. It simply and naively concatenates them, which is insecure and lets an adversary craft a \"cross-linked block\" (block with cross-linked transactions) which alters the way peers process transactions. For example, it is possible to select a transaction and manipulate a peer to completely avoid processing it, without changing the computed hash of the block. Additional validations have been added in v2.2.14 and v2.5.5 to detect potential cross-linking issues before processing blocks. Users are advised to upgrade. There are no known workarounds for this vulnerability.","published":"2023-11-14T20:23:15.643Z","modified":"2026-08-08T03:48:00.573981630Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Go","name":"github.com/hyperledger/fabric","fixedVersion":"2.2.14"},{"ecosystem":"Go","name":"github.com/hyperledger/fabric","fixedVersion":"2.5.5"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/46xxx/CVE-2023-46132.json"},{"type":"ADVISORY","url":"https://github.com/hyperledger/fabric/security/advisories/GHSA-v9w2-543f-h69m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-46132"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:00.573981630Z"}}