{"id":"GHSA-xq4h-wqm2-668w","aliases":["GO-2025-4159"],"url":"https://o3.security/vulnerability/GHSA-xq4h-wqm2-668w","summary":"Babylon's BIP322 signature implementation is not fully compliant to the spec","details":"### Summary\n\nThe BIP-322 signature verification does not enforce the SIGHASH value to be SIGHASH_ALL, and therefore is not strictly following the [spec](https://bips.dev/322/).\n\n### Impact\n\nNon-compliant BIP-322 signatures in proof of possessions can be accepted by the chain.","published":"2025-11-24T23:34:18Z","modified":"2025-11-27T08:58:53.478261Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/babylonlabs-io/babylon/v4","fixedVersion":"4.1.0"}],"fix":{"url":"https://github.com/babylonlabs-io/babylon/commit/6e8bdd328a47343fcd7ad98d1b0c7267860b019a","label":"babylonlabs-io/babylon@6e8bdd3"},"references":[{"type":"WEB","url":"https://github.com/babylonlabs-io/babylon/security/advisories/GHSA-xq4h-wqm2-668w"},{"type":"WEB","url":"https://github.com/babylonlabs-io/babylon/commit/6e8bdd328a47343fcd7ad98d1b0c7267860b019a"},{"type":"WEB","url":"https://bips.dev/322"},{"type":"PACKAGE","url":"https://github.com/babylonlabs-io/babylon"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-11-27T08:58:53.478261Z"}}