CVE-2026-40583

UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance prechecks, but fails authorization only after state mutation has already occurred.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ultradag:ultradag:0.1.0:*:*:*:*:*:*:*

History

27 Apr 2026, 15:23

Type Values Removed Values Added
References () https://github.com/UltraDAGcom/core/commit/2f5a3a237ea519b48d71e6e3093c89f60694c7be - () https://github.com/UltraDAGcom/core/commit/2f5a3a237ea519b48d71e6e3093c89f60694c7be - Patch
References () https://github.com/UltraDAGcom/core/commit/45bcf7064741897319b6196d3d9f9e1307093511 - () https://github.com/UltraDAGcom/core/commit/45bcf7064741897319b6196d3d9f9e1307093511 - Patch
References () https://github.com/UltraDAGcom/core/security/advisories/GHSA-q8wx-2crx-c7pp - () https://github.com/UltraDAGcom/core/security/advisories/GHSA-q8wx-2crx-c7pp - Exploit, Mitigation, Vendor Advisory
CPE cpe:2.3:a:ultradag:ultradag:0.1.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.2
First Time Ultradag
Ultradag ultradag

21 Apr 2026, 21:16

Type Values Removed Values Added
References () https://github.com/UltraDAGcom/core/security/advisories/GHSA-q8wx-2crx-c7pp - () https://github.com/UltraDAGcom/core/security/advisories/GHSA-q8wx-2crx-c7pp -

21 Apr 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-21 17:16

Updated : 2026-04-27 15:23


NVD link : CVE-2026-40583

Mitre link : CVE-2026-40583

CVE.ORG link : CVE-2026-40583


JSON object : View

Products Affected

ultradag

  • ultradag
CWE
CWE-460

Improper Cleanup on Thrown Exception

CWE-696

Incorrect Behavior Order