Technology · crates.io
ckb (crates.io) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 17 vulnerabilities in ckb (crates.io): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, Nervos CKB Pool does not remove the conflicting transactions from the statistics, was published on 3 February 2024.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest ckb (crates.io) vulnerabilities
- Nervos CKB Pool does not remove the conflicting transactions from the statisticsinfo
- Nervos CKB Transaction which calls syscall load_cell_data_hash has nondeterministic resultinfo
- Nervos CKB Snappy decompress length can be very large and causes out of memory errorinfo
- Nervos CKB Panic on malformed inputinfo
- Nervos CKB BlockTimeTooNew should not be considered as invalid blockinfo
- Nervos CKB DoS: Process exists when p2p discovery protocol receives unsupported peer IPinfo
- Nervos CKB P2P DoS Attacksinfo
- Nervos CKB Unaligned Pointer Dereferenceinfo
- Nervos CKB vulnerable to low-resource flood DDoS attacks through network messageinfo
- Nervos CKB calculation of program load cycles may be missed when executing in resume modeinfo
- ckb type_id script resume may randomly failinfo
- ckb: Transaction header_deps validation issue (network forking)info
- ckb: Large dep group requires a lot of resources to process but the cost to commit the transaction is very low.info
- Dep Group Remote Memory Exhaustion (Denial of Service) in ckbinfo
- CVE-2021-45699: RUSTSEC-2021-0108 - Remote memory exhaustion in ckblowCVSS 3.1EPSS 1.5%
- CVE-2021-45700: RUSTSEC-2021-0109 - Process crashes when the cell used as DepGroup is not alivelowCVSS 3.1EPSS 1.1%
- CVE-2021-45698: RUSTSEC-2021-0107 - Miner fails to get block template when a cell used as a cell dep has been destroyed.lowCVSS 3.1EPSS 1.2%
Most severe ckb (crates.io) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2021-45699: RUSTSEC-2021-0108 - Remote memory exhaustion in ckblowCVSS 3.1EPSS 1.5%
- CVE-2021-45698: RUSTSEC-2021-0107 - Miner fails to get block template when a cell used as a cell dep has been destroyed.lowCVSS 3.1EPSS 1.2%
- CVE-2021-45700: RUSTSEC-2021-0109 - Process crashes when the cell used as DepGroup is not alivelowCVSS 3.1EPSS 1.1%
- Nervos CKB Pool does not remove the conflicting transactions from the statisticsinfo
- Nervos CKB Transaction which calls syscall load_cell_data_hash has nondeterministic resultinfo
- Nervos CKB Snappy decompress length can be very large and causes out of memory errorinfo
- Nervos CKB Panic on malformed inputinfo
- Nervos CKB BlockTimeTooNew should not be considered as invalid blockinfo
- Nervos CKB DoS: Process exists when p2p discovery protocol receives unsupported peer IPinfo
- Nervos CKB P2P DoS Attacksinfo
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/ckb.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "ckb (crates.io) vulnerabilities", https://junglewise.ai/threats/technologies/ckb, 27 September 2026.