aries-cloudagent
Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments.
Activity
- Latest release
- 1y ago
- Total releases
- 102
- Cadence
- ~7 days
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Jul 16, 2019
| Version | Released | |
|---|---|---|
0.12.8
patch
|
0.12.8
patch
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.7
patch
|
0.12.7
patch
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.7rc2
pre
|
0.12.7rc2
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.7rc1
pre
|
0.12.7rc1
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.7rc0
pre
|
0.12.7rc0
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.6
patch
|
0.12.6
patch
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.5
patch
|
0.12.5
patch
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.4
patch
|
0.12.4
patch
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.3
patch
|
0.12.3
patch
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.3rc0
pre
|
0.12.3rc0
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
1.0.1
patch
|
1.0.1
patch
Dependencies (39)
+ 31 more
Changelog
Compare changes
|
|
1.0.1rc1
pre
|
1.0.1rc1
pre
Dependencies (39)
+ 31 more
Changelog
Compare changes
|
|
1.0.1rc0
pre
|
1.0.1rc0
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
1.0.0
major
|
1.0.0
major
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
1.0.0rc6
pre
|
1.0.0rc6
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.2
patch
|
0.12.2
patch
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.11.3
patch
|
0.11.3
patch
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
0.12.2rc1
pre
|
0.12.2rc1
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.11.2
patch
|
0.11.2
patch
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
1.0.0rc5
pre
|
1.0.0rc5
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
1.0.0rc4
pre
|
1.0.0rc4
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.11.1
patch
|
0.11.1
patch
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
0.12.1
patch
|
0.12.1
patch
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.1rc1
pre
|
0.12.1rc1
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.1rc0
pre
|
0.12.1rc0
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.0
minor
|
0.12.0
minor
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.0rc3
pre
|
0.12.0rc3
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.0rc2
pre
|
0.12.0rc2
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.0rc1
pre
|
0.12.0rc1
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.12.0rc0
pre
|
0.12.0rc0
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
0.11.0
minor
|
0.11.0
minor
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
0.10.5
patch
| ||
0.11.0rc2
pre
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
0.11.0rc2
pre
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
0.11.0rc1
pre
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev |
0.11.0rc1
pre
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
0.10.4
patch
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
0.10.3
patch
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
0.10.2
patch
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
0.10.2rc0
pre
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
0.10.1
patch
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
0.10.0
minor
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
0.10.0rc2
pre
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
0.10.0rc1
pre
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
0.10.0rc0
pre
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
0.9.0
minor
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
0.9.0rc0
pre
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
1.0.0rc3
pre
| ||
0.8.2
patch
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
0.8.2rc2
pre
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
0.8.2rc1
pre
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev | ||
0.8.2rc0
pre
1 CVE
CVE-2024-21669
PYSEC-2026-284
GHSA-97x9-59rv-q5pm
Jun 29, 2026
Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
Low
ImpactWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation
The flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own. This vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0. All ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability. PatchesThis issue has been patched in version 0.10.5 and fixed in 0.11.0. WorkaroundsThere is no workaround other upgrading to a patched/fixed version of ACA-Py. Affected versions
0.10.0
0.10.0rc0
0.10.0rc1
0.10.0rc2
0.10.1
0.10.2
0.10.2rc0
0.10.3
0.10.4
0.11.0rc1
0.11.0rc2
0.7.0
+ 28 more Show less
0.7.1
0.7.1rc0
0.7.2
0.7.2rc0
0.7.3
0.7.3rc0
0.7.4
0.7.4rc0
0.7.4rc1
0.7.4rc2
0.7.4rc3
0.7.4rc4
0.7.4rc5
0.7.5
0.7.5rc0
0.7.5rc1
0.8.0
0.8.0rc0
0.8.1
0.8.1rc0
0.8.1rc1
0.8.1rc2
0.8.2
0.8.2rc0
0.8.2rc1
0.8.2rc2
0.9.0
0.9.0rc0
Fixed in
0.10.5
0.11.0
References
Updated Jul 02, 2026 · Source: OSV.dev |