Executive brief
The Hyperledger Fabric SDK for Java, a tool used by applications to interact with blockchain networks, contains a security flaw in how it handles saved data. An attacker who can provide a specially crafted data file to an application using this SDK can take complete control of the system running that application. This could lead to the theft of sensitive blockchain credentials, unauthorized transactions, or a total shutdown of the affected service.
Technical details
A Java deserialization vulnerability exists in the `Channel.java` component of `fabric-sdk-java`. The `readObject()` and `deSerializeChannel()` methods utilize `ObjectInputStream.readObject()` on byte arrays without implementing an `ObjectInputFilter`. An attacker can exploit this by providing a malicious serialized object (e.g., via a compromised local channel file or an application endpoint that accepts channel bytes), leading to Remote Code Execution (RCE) through gadget chain exploitation. This SDK is deprecated; users are advised to migrate to `fabric-gateway`, which avoids Java serialization.
Affected products
- Hyperledger fabric-sdk-java >= 1.0.0, <= 2.2.26
Timeline
- 2026-04-22: disclosed: Vulnerability reported by Martin Brodeur
- 2026-04-29: advisory: GHSA published
- 2026-05-07: other: NVD published CVE-2026-41586