Hyperledger Fabric versions through 3.0.0 and 2.5.x through 2.5.9 fail to verify that incoming requests contain a timestamp within the expected time window. This allows requests with stale or future timestamps to be processed, bypassing intended temporal validation controls.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a Proof-of-Concept (PoC) demonstrating the risk of transaction time manipulation in Hyperledger Fabric blockchain environments and how to mitigate it. It contains four Go-based chaincode variants: 1. **time_insecure**: Implements a vulnerable chaincode that uses the transaction timestamp (GetTxTimestamp) to calculate interest on a deposit. This allows an attacker to manipulate the local client time and gain unauthorized financial benefits (e.g., by moving the time forward to accrue more interest). 2. **time_secure_ntp**: Uses an external NTP server (0.beevik-ntp.pool.ntp.org) to validate the transaction time, mitigating the attack by comparing the blockchain timestamp to a trusted time source. 3. **time_secure_nts**: Uses an NTS server (time.cloudflare.com) for secure time validation, providing stronger protection against spoofing than plain NTP. 4. **time_secure_localtime**: Compares the transaction time to the local time of the peer node, providing a basic mitigation (though it requires all peer nodes to have correct time). Each chaincode provides functions for staking a deposit, checking dividends, and calculating time differences. The PoC demonstrates both the attack (in the insecure variant) and the effectiveness of mitigations (in the secure variants). The repository is structured with separate directories for each chaincode variant, each containing Go source code and Go module files. The main attack vector is through manipulation of blockchain transaction timestamps, and the code highlights the importance of using secure time sources in smart contract logic. The endpoints used for time validation (NTP/NTS servers) are fingerprintable and may be relevant for further analysis or monitoring.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.