Improper Verification of Cryptographic Signature Affecting github.com/babylonlabs-io/babylon/x/btcstaking/types package, versions >=0.0.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMBABYLONLABSIOBABYLONXBTCSTAKINGTYPES-14105152
  • published25 Nov 2025
  • disclosed24 Nov 2025
  • creditUnknown

Introduced: 24 Nov 2025

New CVE NOT AVAILABLE CWE-347  (opens in a new tab)

How to fix?

Upgrade github.com/babylonlabs-io/babylon/x/btcstaking/types to version or higher.

Overview

Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature due to improper enforcement of the SIGHASH value in the signature verification process. An attacker can submit non-compliant signatures that are incorrectly accepted as valid by providing signatures that do not meet the required specification.

References

CVSS Base Scores

version 4.0
version 3.1