CVE-2026-41586
CRITICALHyperledger Fabric 1.0.0-2.2.26 fabric-sdk-java - Java Deserialization Remote Code Execution
Title source: manualDescription
Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays without configuring an ObjectInputFilter. This is a classic Java deserialization RCE pattern. At time of publication, there are no publicly available patches.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/hyperledger/fabric/security/advisories/GHSA-prf8-cf2x-rhx7
X_Refsource_Misc x_refsource_misc
https://hyperledger.github.io/fabric-gateway
Scores
CVSS v4
9.3
EPSS
0.0041
EPSS Percentile
32.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-502
Status
published
Products (2)
hyperledger/fabric
>= 1.0.0, <= 2.2.26
org.hyperledger.fabric-sdk-java/fabric-sdk-java
1.0.0 - 2.2.26Maven
Published
May 07, 2026
Tracked Since
May 07, 2026