CVE-2026-40069
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: security-advisories@github.com (Secondary)
Description
BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.1.0 to before 0.8.2, BSV::Network::ARC's failure detection only recognises REJECTED and DOUBLE_SPEND_ATTEMPTED. ARC responses with txStatus values of INVALID, MALFORMED, MINED_IN_STALE_BLOCK, or any ORPHAN-containing extraInfo / txStatus are silently treated as successful broadcasts. Applications that gate actions on broadcaster success are tricked into trusting transactions that were never accepted by the network. This vulnerability is fixed in 0.8.2.
Affected (1)
Products: Sgbett: Bsv Ruby Sdk
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 0.1.0 to 0.8.2 |
References (5)
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
PatchVendor Advisory
Timeline
No history available yet.