CometBFT has inconsistencies between how commit signatures are verified and how block time is derived
CometBFT has inconsistencies between how commit signatures are verified and how block time is derived. Name: CSA-2026-001: Tachyon Criticality: Critical (Catastrophic Impact; Possible Likelihood per ACMv1.
Vuln-watch · relayed from the GitHub Advisory Database; see Source & attribution below
Summary
Name: CSA-2026-001: Tachyon Criticality: Critical (Catastrophic Impact; Possible Likelihood per ACMv1.2) Affected versions: All versions of CometBFT Affected users: Validators and protocols relying on block timestamps A consensus-level vulnerability was discovered in CometBFT's "BFT Time" implementation due to an inconsistency between how commit signatures are verified and how block time is derived.
Affected
- github.com/cometbft/cometbft (go) >= 0.38.0-alpha.1, <= 0.38.20 — fixed in 0.38.21
- github.com/cometbft/cometbft (go) <= 0.37.17 — fixed in 0.37.18
Severity
High (CVSS 7.1), as rated by the upstream advisory.
Recommended actions
- Upgrade github.com/cometbft/cometbft to 0.38.21 or later
- Upgrade github.com/cometbft/cometbft to 0.37.18 or later
Source & attribution
This 0xCERT advisory summarises GHSA-c32p-wcqj-j677 from the GitHub Advisory Database: https://github.com/advisories/GHSA-c32p-wcqj-j677. Details may change; refer to the original source for the authoritative record.
References
- https://github.com/advisories/GHSA-c32p-wcqj-j677
- https://github.com/cometbft/cometbft/security/advisories/GHSA-c32p-wcqj-j677
- https://github.com/cometbft/cometbft/commit/bf8274fcdbcab2bc652660ae627196a90a6efb97
- https://github.com/cometbft/cometbft/releases/tag/v0.37.18
- https://github.com/cometbft/cometbft/releases/tag/v0.38.21
- https://pkg.go.dev/vuln/GO-2026-4361
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-01-23 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0217/signed.txt | gpg --verify