-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0217 ============================================================ Advisory-ID: 0xCERT-2026-0217 Severity: High Published: 2026-01-23T16:56:23.000Z Updated: 2026-10-08T22:48:25.826Z Chains: Cosmos Hub URL: https://www.0xcert.com/advisory/0xCERT-2026-0217 Title: CometBFT has inconsistencies between how commit signatures are verified and how block time is derived Summary - ------- CometBFT has inconsistencies between how commit signatures are verified and how block time is derived. Name: CSA-2026-001: Tachyon Criticality: Critical (Catastrophic Impact; Possible Likelihood per ACMv1. Details - ------- Summary Name: CSA-2026-001: Tachyon Criticality: Critical (Catastrophic Impact; Possible Likelihood per ACMv1.2) Affected versions: All versions of CometBFT Affected users: Validators and protocols relying on block timestamps A consensus-level vulnerability was discovered in CometBFT's "BFT Time" implementation due to an inconsistency between how commit signatures are verified and how block time is derived. Affected - - github.com/cometbft/cometbft (go) >= 0.38.0-alpha.1, <= 0.38.20 — fixed in 0.38.21 - - github.com/cometbft/cometbft (go) <= 0.37.17 — fixed in 0.37.18 Severity High (CVSS 7.1), as rated by the upstream advisory. Recommended actions - - Upgrade github.com/cometbft/cometbft to 0.38.21 or later - - Upgrade github.com/cometbft/cometbft to 0.37.18 or later Source & attribution This 0xCERT advisory summarises GHSA-c32p-wcqj-j677 from the GitHub Advisory Database: https://github.com/advisories/GHSA-c32p-wcqj-j677. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://github.com/advisories/GHSA-c32p-wcqj-j677 - - https://github.com/cometbft/cometbft/security/advisories/GHSA-c32p-wcqj-j677 - - https://github.com/cometbft/cometbft/commit/bf8274fcdbcab2bc652660ae627196a90a6efb97 - - https://github.com/cometbft/cometbft/releases/tag/v0.37.18 - - https://github.com/cometbft/cometbft/releases/tag/v0.38.21 - - https://pkg.go.dev/vuln/GO-2026-4361 Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrI9YEJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmf0VfqUaXtJd/nR5sU9pud4YREvr2qjjt5huI5+ qMCj5RYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAAD65wEA4JAfLHKHgrCaxTXN KjHEc5eezgntz1qtr/BaHRmYeTEA/Ro3R/F0uoB82+A4nIWcNE1ZlqbQfKwR VNbTxSlw0ngL =7OaB -----END PGP SIGNATURE-----