CVE-2026-45581

MEDIUM

fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode

Title source: cna
STIX 2.1

Description

fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An attacker with access to the chaincode server logs could recover the TLS private key password. If the attacker can also obtain the TLS private key, they could impersonate the chaincode server. This issue has been patched in version 2.5.10.

References (1)

Core 1

Scores

CVSS v3 5.5
EPSS 0.0011
EPSS Percentile 1.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (2)
hyperledger/fabric-chaincode-java >= 2.3.1, < 2.5.10
org.hyperledger.fabric-chaincode-java/fabric-chaincode-shim 2.3.1 - 2.5.10Maven
Published Jun 08, 2026
Tracked Since Jun 08, 2026