Authentication Bypass by Primary Weakness Affecting github.com/filecoin-project/go-f3/gpbft package, versions <0.8.9


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (10th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMFILECOINPROJECTGOF3GPBFT-13147718
  • published30 Sept 2025
  • disclosed29 Sept 2025
  • creditlgprbs

Introduced: 29 Sep 2025

NewCVE-2025-59941  (opens in a new tab)
CWE-305  (opens in a new tab)

How to fix?

Upgrade github.com/filecoin-project/go-f3/gpbft to version 0.8.9 or higher.

Overview

Affected versions of this package are vulnerable to Authentication Bypass by Primary Weakness via the justification verification process. An attacker can influence consensus decisions and potentially disrupt network liveness by reusing cached justifications in inappropriate message contexts.

Note: This vulnerability requires significant power (350+ TiB) to exploit meaningfully

References

CVSS Base Scores

version 4.0
version 3.1