CVE-2019-16761

MEDIUM5.7EPSS 0.37%

Validation Bypass in slp-validate

Published: 11/15/2019Modified: 3/13/2026
Also known as:GHSA-wmx6-vxcf-c3gr

Description

Versions of `slp-validate` prior to 1.0.1 are vulnerable to a validation bypass. Bitcoin scripts may cause the validation result from `slp-validate` to differ from the specified SLP consensus. This allows an attacker to create a Bitcoin script that causes a hard-fork from the SLP consensus. ## Recommendation Upgrade to version 1.0.1 or later.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.7CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:H

References (5)