{"id":"GHSA-c32p-wcqj-j677","aliases":["GO-2026-4361"],"url":"https://o3.security/vulnerability/GHSA-c32p-wcqj-j677","summary":"CometBFT has inconsistencies between how commit signatures are verified and how block time is derived","details":"# CSA-2026-001: Tachyon\n\n## Description\n\n**Name:** CSA-2026-001: Tachyon\n\n**Criticality:** Critical (Catastrophic Impact; Possible Likelihood per [ACMv1.2](https://github.com/interchainio/security/blob/main/resources/CLASSIFICATION_MATRIX.md))\n\n**Affected versions:** All versions of CometBFT\n\n**Affected users:** Validators and protocols relying on block timestamps\n\n## Description\n\nA consensus-level vulnerability was discovered in CometBFT's \"BFT Time\" implementation due to an inconsistency between how commit signatures are verified and how block time is derived.\n\nThis breaks a core BFT Time guarantee: \"A faulty process cannot arbitrarily increase the Time value.\"\n\n## Impact\n\nDownstream impact on chains affects any module, smart contract, or system that relies on the block timestamp.\n\n## Patches\n\nThe new CometBFT releases [v0.38.21](https://github.com/cometbft/cometbft/releases/tag/v0.38.21) and [v0.37.18](https://github.com/cometbft/cometbft/releases/tag/v0.37.18) fix this issue. The `main` unreleased branch is also patched.\n\n## Workarounds\n\nThere are no effective workarounds for this vulnerability. Upgrading to patched versions is required.\n\n## Timeline\n\n- January 8, 2026, 5:27PM UTC: Issue reported to Cosmos Bug Bounty Program\n- January 9, 2026, 4:55AM UTC: Issue triaged and validated by core team\n- January 12, 2026, 10:25PM UTC: Core team completes patch for the issue\n- January 13, 2026 4:41PM UTC: Pre-notification delivered to ecosystem partners\n- January 23, 2026, 3:00PM UTC: Patch made available\n\n## Credits\n\nThis issue was reported to the Cosmos Bug Bounty Program on HackerOne. Credit to SEAL 911 and [QED Audit](https://x.com/QED_Audit) for the discovery and help with the patch.\n\nIf you believe you have found a bug in the Cosmos Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos.\n\nIf you have questions about Cosmos security efforts, please reach out to our official communication channel at security@cosmoslabs.io.\n\nA Github Security Advisory for this issue is available in the CometBFT repository. For more information about CometBFT, see https://docs.cometbft.com/.","published":"2026-01-23T16:56:23Z","modified":"2026-02-28T05:13:47.205461Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/cometbft/cometbft","fixedVersion":"0.38.21"},{"ecosystem":"Go","name":"github.com/cometbft/cometbft","fixedVersion":"0.37.18"}],"fix":{"url":"https://github.com/cometbft/cometbft/commit/bf8274fcdbcab2bc652660ae627196a90a6efb97","label":"cometbft/cometbft@bf8274f"},"references":[{"type":"WEB","url":"https://github.com/cometbft/cometbft/security/advisories/GHSA-c32p-wcqj-j677"},{"type":"WEB","url":"https://github.com/cometbft/cometbft/commit/bf8274fcdbcab2bc652660ae627196a90a6efb97"},{"type":"PACKAGE","url":"https://github.com/cometbft/cometbft"},{"type":"WEB","url":"https://github.com/cometbft/cometbft/releases/tag/v0.37.18"},{"type":"WEB","url":"https://github.com/cometbft/cometbft/releases/tag/v0.38.21"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2026-4361"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-28T05:13:47.205461Z"}}