soroban-sdk
Rust SDK for Soroban contracts.
Activity
- Latest release
- 2w ago
- Total releases
- 131
- Cadence
- ~5 days
- Last 12 months
- 39
Reach
- Downloads
- 1.5M
- Stars
- 199
Details
- License
- Apache-2.0
- First release
- Jul 28, 2022
| Version | Released | |
|---|---|---|
28.0.0-rc.1
pre
|
28.0.0-rc.1
pre
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
27.0.6
patch
|
27.0.6
patch
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
27.0.5
patch
|
27.0.5
patch
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
27.0.4
patch
|
27.0.4
patch
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
27.0.3
patch
|
27.0.3
patch
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
27.0.2
patch
|
27.0.2
patch
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
27.0.1
patch
|
27.0.1
patch
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
26.1.1
patch
|
26.1.1
patch
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
25.3.2
patch
|
25.3.2
patch
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
27.0.0
major
|
27.0.0
major
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
27.0.0-rc.1
pre
|
27.0.0-rc.1
pre
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
26.1.0
minor
|
26.1.0
minor
Dependencies (37)
+ 29 more
Changelog
Compare changes
|
|
26.0.1
patch
|
26.0.1
patch
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
26.0.0
major
|
26.0.0
major
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
26.0.0-rc.1
pre
|
26.0.0-rc.1
pre
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
25.3.1
patch
|
25.3.1
patch
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
23.5.3
patch
|
23.5.3
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
22.0.11
patch
|
22.0.11
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
25.3.0
minor
|
25.3.0
minor
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
25.2.0
minor
1 CVE
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev |
25.2.0
minor
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
23.5.2
patch
1 CVE
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev |
23.5.2
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
22.0.10
patch
1 CVE
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev |
22.0.10
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
25.1.1
patch
1 CVE
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev |
25.1.1
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
25.1.0
minor
1 CVE
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev |
25.1.0
minor
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
22.0.9
patch
1 CVE
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev |
22.0.9
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
23.5.1
patch
1 CVE
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev |
23.5.1
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
25.0.2
patch
1 CVE
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev |
25.0.2
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
23.5.0
minor
2 CVEs
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev
CVE-2026-24889
GHSA-96xm-fv9w-pf3f
Jan 28, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactArithmetic overflow can be triggered in the Contracts that pass user-controlled or computed range bounds to Note that the best practice when using the DetailWhen compiled with
Note that some cases where the overflow was permitted and wrapped on the guest side are caught by the Soroban Env Host and cause a trap host side with error
PatchesThe fix replaces bare arithmetic with WorkaroundsContract workspaces can be configured with the following profile to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using
Alternatively, contracts can validate range bounds before passing them to
References
Fixed in
22.0.9
23.5.1
25.0.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
23.5.0
minor
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
25.0.1
patch
2 CVEs
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev
CVE-2026-24889
GHSA-96xm-fv9w-pf3f
Jan 28, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactArithmetic overflow can be triggered in the Contracts that pass user-controlled or computed range bounds to Note that the best practice when using the DetailWhen compiled with
Note that some cases where the overflow was permitted and wrapped on the guest side are caught by the Soroban Env Host and cause a trap host side with error
PatchesThe fix replaces bare arithmetic with WorkaroundsContract workspaces can be configured with the following profile to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using
Alternatively, contracts can validate range bounds before passing them to
References
Fixed in
22.0.9
23.5.1
25.0.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
25.0.1
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
25.0.0
major
2 CVEs
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev
CVE-2026-24889
GHSA-96xm-fv9w-pf3f
Jan 28, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactArithmetic overflow can be triggered in the Contracts that pass user-controlled or computed range bounds to Note that the best practice when using the DetailWhen compiled with
Note that some cases where the overflow was permitted and wrapped on the guest side are caught by the Soroban Env Host and cause a trap host side with error
PatchesThe fix replaces bare arithmetic with WorkaroundsContract workspaces can be configured with the following profile to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using
Alternatively, contracts can validate range bounds before passing them to
References
Fixed in
22.0.9
23.5.1
25.0.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
25.0.0
major
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
25.0.0-rc.2
pre
|
25.0.0-rc.2
pre
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
23.4.1
patch
2 CVEs
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev
CVE-2026-24889
GHSA-96xm-fv9w-pf3f
Jan 28, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactArithmetic overflow can be triggered in the Contracts that pass user-controlled or computed range bounds to Note that the best practice when using the DetailWhen compiled with
Note that some cases where the overflow was permitted and wrapped on the guest side are caught by the Soroban Env Host and cause a trap host side with error
PatchesThe fix replaces bare arithmetic with WorkaroundsContract workspaces can be configured with the following profile to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using
Alternatively, contracts can validate range bounds before passing them to
References
Fixed in
22.0.9
23.5.1
25.0.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
23.4.1
patch
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
25.0.0-rc.1
pre
|
25.0.0-rc.1
pre
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
23.4.0
minor
2 CVEs
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev
CVE-2026-24889
GHSA-96xm-fv9w-pf3f
Jan 28, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactArithmetic overflow can be triggered in the Contracts that pass user-controlled or computed range bounds to Note that the best practice when using the DetailWhen compiled with
Note that some cases where the overflow was permitted and wrapped on the guest side are caught by the Soroban Env Host and cause a trap host side with error
PatchesThe fix replaces bare arithmetic with WorkaroundsContract workspaces can be configured with the following profile to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using
Alternatively, contracts can validate range bounds before passing them to
References
Fixed in
22.0.9
23.5.1
25.0.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
23.4.0
minor
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
23.3.0
minor
2 CVEs
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev
CVE-2026-24889
GHSA-96xm-fv9w-pf3f
Jan 28, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactArithmetic overflow can be triggered in the Contracts that pass user-controlled or computed range bounds to Note that the best practice when using the DetailWhen compiled with
Note that some cases where the overflow was permitted and wrapped on the guest side are caught by the Soroban Env Host and cause a trap host side with error
PatchesThe fix replaces bare arithmetic with WorkaroundsContract workspaces can be configured with the following profile to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using
Alternatively, contracts can validate range bounds before passing them to
References
Fixed in
22.0.9
23.5.1
25.0.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
23.3.0
minor
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
23.2.1
minor
2 CVEs
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev
CVE-2026-24889
GHSA-96xm-fv9w-pf3f
Jan 28, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactArithmetic overflow can be triggered in the Contracts that pass user-controlled or computed range bounds to Note that the best practice when using the DetailWhen compiled with
Note that some cases where the overflow was permitted and wrapped on the guest side are caught by the Soroban Env Host and cause a trap host side with error
PatchesThe fix replaces bare arithmetic with WorkaroundsContract workspaces can be configured with the following profile to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using
Alternatively, contracts can validate range bounds before passing them to
References
Fixed in
22.0.9
23.5.1
25.0.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
23.2.1
minor
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
23.1.1
patch
2 CVEs
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev
CVE-2026-24889
GHSA-96xm-fv9w-pf3f
Jan 28, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactArithmetic overflow can be triggered in the Contracts that pass user-controlled or computed range bounds to Note that the best practice when using the DetailWhen compiled with
Note that some cases where the overflow was permitted and wrapped on the guest side are caught by the Soroban Env Host and cause a trap host side with error
PatchesThe fix replaces bare arithmetic with WorkaroundsContract workspaces can be configured with the following profile to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using
Alternatively, contracts can validate range bounds before passing them to
References
Fixed in
22.0.9
23.5.1
25.0.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
23.1.1
patch
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
23.1.0
minor
2 CVEs
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev
CVE-2026-24889
GHSA-96xm-fv9w-pf3f
Jan 28, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactArithmetic overflow can be triggered in the Contracts that pass user-controlled or computed range bounds to Note that the best practice when using the DetailWhen compiled with
Note that some cases where the overflow was permitted and wrapped on the guest side are caught by the Soroban Env Host and cause a trap host side with error
PatchesThe fix replaces bare arithmetic with WorkaroundsContract workspaces can be configured with the following profile to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using
Alternatively, contracts can validate range bounds before passing them to
References
Fixed in
22.0.9
23.5.1
25.0.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
23.1.0
minor
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
23.0.3
patch
2 CVEs
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev
CVE-2026-24889
GHSA-96xm-fv9w-pf3f
Jan 28, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactArithmetic overflow can be triggered in the Contracts that pass user-controlled or computed range bounds to Note that the best practice when using the DetailWhen compiled with
Note that some cases where the overflow was permitted and wrapped on the guest side are caught by the Soroban Env Host and cause a trap host side with error
PatchesThe fix replaces bare arithmetic with WorkaroundsContract workspaces can be configured with the following profile to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using
Alternatively, contracts can validate range bounds before passing them to
References
Fixed in
22.0.9
23.5.1
25.0.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
23.0.3
patch
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
23.0.2
patch
2 CVEs
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev
CVE-2026-24889
GHSA-96xm-fv9w-pf3f
Jan 28, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactArithmetic overflow can be triggered in the Contracts that pass user-controlled or computed range bounds to Note that the best practice when using the DetailWhen compiled with
Note that some cases where the overflow was permitted and wrapped on the guest side are caught by the Soroban Env Host and cause a trap host side with error
PatchesThe fix replaces bare arithmetic with WorkaroundsContract workspaces can be configured with the following profile to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using
Alternatively, contracts can validate range bounds before passing them to
References
Fixed in
22.0.9
23.5.1
25.0.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
23.0.2
patch
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
23.0.1
patch
2 CVEs
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev
CVE-2026-24889
GHSA-96xm-fv9w-pf3f
Jan 28, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactArithmetic overflow can be triggered in the Contracts that pass user-controlled or computed range bounds to Note that the best practice when using the DetailWhen compiled with
Note that some cases where the overflow was permitted and wrapped on the guest side are caught by the Soroban Env Host and cause a trap host side with error
PatchesThe fix replaces bare arithmetic with WorkaroundsContract workspaces can be configured with the following profile to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using
Alternatively, contracts can validate range bounds before passing them to
References
Fixed in
22.0.9
23.5.1
25.0.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
23.0.1
patch
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
23.0.0
major
2 CVEs
CVE-2026-32322
GHSA-x2hw-px52-wp4m
Mar 13, 2026
rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
Security Advisory: Incorrect Equality for Fr Scalar Field Types (BN254, BLS12-381)SummaryMissing modular reduction in ImpactThe The vulnerability requires an attacker to supply crafted Smart contracts that rely on Details
This issue was compounded by an asymmetry: all host-side arithmetic operations ( Example
PatchesAll Additionally, WorkaroundsIf upgrading is not immediately possible:
Recommendations
Fixed in
22.0.11
23.5.3
25.3.0
References
Updated Mar 16, 2026 · Source: OSV.dev
CVE-2026-24889
GHSA-96xm-fv9w-pf3f
Jan 28, 2026
soroban-sdk has overflow in Bytes::slice, Vec::slice, GenRange::gen_range for u64
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactArithmetic overflow can be triggered in the Contracts that pass user-controlled or computed range bounds to Note that the best practice when using the DetailWhen compiled with
Note that some cases where the overflow was permitted and wrapped on the guest side are caught by the Soroban Env Host and cause a trap host side with error
PatchesThe fix replaces bare arithmetic with WorkaroundsContract workspaces can be configured with the following profile to enable overflow checks on the arithmetic operations. This is the best practice when developing Soroban contracts, and the default if using the contract boilerplate generated using
Alternatively, contracts can validate range bounds before passing them to
References
Fixed in
22.0.9
23.5.1
25.0.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
23.0.0
major
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
23.0.0-rc.3
pre
|
23.0.0-rc.3
pre
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
23.0.0-rc.2.4
pre
|
23.0.0-rc.2.4
pre
Dependencies (31)
+ 23 more
Changelog
Compare changes
|
|
23.0.0-rc.2.3
pre
|
23.0.0-rc.2.3
pre
Dependencies (31)
+ 23 more
Changelog
Compare changes
|
|
23.0.0-rc.2.2
pre
|
23.0.0-rc.2.2
pre
Dependencies (31)
+ 23 more
Changelog
Compare changes
|
|
23.0.0-rc.2.1
pre
|
23.0.0-rc.2.1
pre
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
23.0.0-rc.2
pre
|
23.0.0-rc.2
pre
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
23.0.0-rc.1.1
pre
|
23.0.0-rc.1.1
pre
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
23.0.0-rc.1
pre
|
23.0.0-rc.1
pre
Dependencies (30)
+ 22 more
Changelog
Compare changes
|