CVE-2026-45581

fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An attacker with access to the chaincode server logs could recover the TLS private key password. If the attacker can also obtain the TLS private key, they could impersonate the chaincode server. This issue has been patched in version 2.5.10.
Configurations

No configuration.

History

08 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-08 17:16

Updated : 2026-06-17 10:52


NVD link : CVE-2026-45581

Mitre link : CVE-2026-45581

CVE.ORG link : CVE-2026-45581


JSON object : View

Products Affected

No product.

CWE
CWE-532

Insertion of Sensitive Information into Log File