maven package report

Is org.hyperledger.fabric-sdk-java:fabric-sdk-java safe?

1 known vulnerability, worst severity CRITICAL.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


      cvss
      0.0
      critical

      severity out of 10

      epss
      0.00%
      medium

      chance of exploitation in 30 days, 48th percentile of all CVEs

      xyz score
      0.0
      medium

      CyberXYZ composite out of 10

      fig. 01 — GHSA-prf8-cf2x-rhx7, the advisory selected below

      // 1 advisories

      GHSA-prf8-cf2x-rhx7

      CRITICALCVE-2026-41586
      // summary

      This advisory covers the deprecated fabric-sdk-java client SDK. Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays without configuring an ObjectInputFilter. This is the classic Java deserialization RCE pattern.

      Note: fabric-sdk-java is deprecated and maintained in https://github.com/hyperledger/fabric-sdk-java. Filing here as that repo does not have private vulnerability reporting enabled.

      // affected code
      // src/main/java/org/hyperledger/fabric/sdk/Channel.java
      private void readObject(ObjectInputStream in) throws IOException, ClassNotFoundException {
          in.defaultReadObject();  // No ObjectInputFilter configured
      }
      
      public Channel deSerializeChannel(byte[] channelBytes)
              throws IOException, ClassNotFoundException, InvalidArgumentException {
          ObjectInputStream ois = new ObjectInputStream(new ByteArrayInputStream(channelBytes));
          Channel channel = (Channel) ois.readObject();  // Untrusted bytes deserialized
          return channel;
      }
      // attack vector

      An attacker who can supply crafted serialized Channel bytes to the client application — for example, by compromising a local channel file, injecting data through an application that accepts Channel bytes from external sources, or exploiting a separate write primitive — can achieve RCE via gadget chain exploitation when deSerializeChannel() processes those bytes. The risk is highest in deployments that accept Channel data from sources outside the client's direct control. Note: channel data is not transmitted from Fabric peers; this is a client-side deserialization surface.

      // proof of concept
      // Generate malicious payload with ysoserial:
      // java -jar ysoserial.jar CommonsCollections6 "touch /tmp/pwned" > malicious_channel.ser
      
      // Victim code:
      byte[] maliciousBytes = Files.readAllBytes(Paths.get("malicious_channel.ser"));
      Channel channel = client.deSerializeChannel(maliciousBytes);  // RCE fires here
      // notes on deprecation

      fabric-sdk-java is deprecated as of Hyperledger Fabric v2.5 (replaced by org.hyperledger.fabric:fabric-gateway). However, organizations that have not yet migrated remain fully exposed. Automated dependency scanners (Snyk, Dependabot) cannot alert users without a published GHSA. This advisory is filed to ensure those users are notified and directed to migrate.

      // fix

      For the deprecated SDK: add ObjectInputFilter to whitelist only expected classes:

      ObjectInputFilter filter = ObjectInputFilter.Config.createFilter(
          "org.hyperledger.fabric.sdk.*;java.util.*;java.lang.*;!*"
      );
      ois.setObjectInputFilter(filter);

      The recommended remediation is migration to org.hyperledger.fabric:fabric-gateway, which does not use Java serialization.

      // resources// credits

      Found by Martin Brodeur (brodmart) via independent security research.

      // cvss v4.0 vector

      CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

      Attack vector
      Network
      Attack complexity
      Low
      Attack requirements
      None
      Privileges required
      None
      User interaction
      None
      Confidentiality (vulnerable system)
      High
      Integrity (vulnerable system)
      High
      Availability (vulnerable system)
      High
      Confidentiality (subsequent systems)
      None
      Integrity (subsequent systems)
      None
      Availability (subsequent systems)
      None

      Checked 2026-10-04 at 02:18 UTC. The most recent advisory here was published 2026-04-29. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.