CVE-2026-40583
HIGHUltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
Title source: cnaDescription
UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance prechecks, but fails authorization only after state mutation has already occurred.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/UltraDAGcom/core/security/advisories/GHSA-q8wx-2crx-c7pp
X_Refsource_Misc x_refsource_misc
https://github.com/UltraDAGcom/core/commit/2f5a3a237ea519b48d71e6e3093c89f60694c7be
X_Refsource_Misc x_refsource_misc
https://github.com/UltraDAGcom/core/commit/45bcf7064741897319b6196d3d9f9e1307093511
Scores
CVSS v3
8.2
EPSS
0.0038
EPSS Percentile
29.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-460
CWE-696
Status
published
Products (2)
ultradag/ultradag
0.1.0
UltraDAGcom/core
= 0.1
Published
Apr 21, 2026
Tracked Since
Apr 21, 2026