Skip to content
Latest alertgo-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash
0xCERT
All advisories
High0xCERT-2026-0217·

CometBFT has inconsistencies between how commit signatures are verified and how block time is derived

CometBFT has inconsistencies between how commit signatures are verified and how block time is derived. Name: CSA-2026-001: Tachyon Criticality: Critical (Catastrophic Impact; Possible Likelihood per ACMv1.

Vuln-watch · relayed from the GitHub Advisory Database; see Source & attribution below

Affected chainsCosmos Hub

Summary

Name: CSA-2026-001: Tachyon Criticality: Critical (Catastrophic Impact; Possible Likelihood per ACMv1.2) Affected versions: All versions of CometBFT Affected users: Validators and protocols relying on block timestamps A consensus-level vulnerability was discovered in CometBFT's "BFT Time" implementation due to an inconsistency between how commit signatures are verified and how block time is derived.

Affected

  • github.com/cometbft/cometbft (go) >= 0.38.0-alpha.1, <= 0.38.20 — fixed in 0.38.21
  • github.com/cometbft/cometbft (go) <= 0.37.17 — fixed in 0.37.18

Severity

High (CVSS 7.1), as rated by the upstream advisory.

Recommended actions

  • Upgrade github.com/cometbft/cometbft to 0.38.21 or later
  • Upgrade github.com/cometbft/cometbft to 0.37.18 or later

Source & attribution

This 0xCERT advisory summarises GHSA-c32p-wcqj-j677 from the GitHub Advisory Database: https://github.com/advisories/GHSA-c32p-wcqj-j677. Details may change; refer to the original source for the authoritative record.

OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.

Published 2026-01-23 · last updated 2026-10-08

curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0217/signed.txt | gpg --verify