CVE Explorer
CVE-2026-26267
soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` macro contains a bug in how it wires up function calls. `#[contractimpl]` generates code that uses `MyContract::value()` style calls even when it's processing the trait version. This means if an inherent function is also defined with the same name, the inherent function gets called instead of the trait function. This means the Wasm-exported entry point silently calls the wrong fu
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"rs-soroban-sdk","vendor":"stellar","versions":[{"status":"affected","version":">= 25.0.0, < 25.1.1"},{"status":"affected","version":">= 23.0.0, < 23.5.2"},{"status":"affected","version":"< 22.0.10"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:92cce1f432283a2b533ecc54b8b778cf5a340d5d1e61b11292d8595d81070f6c · sha256:ad159442c3248d0c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:92cce1f432283a2b533ecc54b8b778cf5a340d5d1e61b11292d8595d81070f6c · sha256:ad159442c3248d0c… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-670","description":"CWE-670: Always-Incorrect Control Flow Implementation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:92cce1f432283a2b533ecc54b8b778cf5a340d5d1e61b11292d8595d81070f6c · sha256:ad159442c3248d0c… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/stellar/rs-soroban-sdk/commit/e92a3933e5f92dc09da3c740cf6a360d55709a2b","tags":["x_refsource_MISC"],"url":"https://github.com/stellar/rs-soroban-sdk/commit/e92a3933e5f92dc09da3c740cf6a360d55709a2b"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:92cce1f432283a2b533ecc54b8b778cf5a340d5d1e61b11292d8595d81070f6c · sha256:ad159442c3248d0c… · /containers/cna/references/4
{"name":"https://github.com/stellar/rs-soroban-sdk/pull/1729","tags":["x_refsource_MISC"],"url":"https://github.com/stellar/rs-soroban-sdk/pull/1729"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:92cce1f432283a2b533ecc54b8b778cf5a340d5d1e61b11292d8595d81070f6c · sha256:ad159442c3248d0c… · /containers/cna/references/1
{"name":"https://github.com/stellar/rs-soroban-sdk/pull/1730","tags":["x_refsource_MISC"],"url":"https://github.com/stellar/rs-soroban-sdk/pull/1730"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:92cce1f432283a2b533ecc54b8b778cf5a340d5d1e61b11292d8595d81070f6c · sha256:ad159442c3248d0c… · /containers/cna/references/2
{"name":"https://github.com/stellar/rs-soroban-sdk/pull/1731","tags":["x_refsource_MISC"],"url":"https://github.com/stellar/rs-soroban-sdk/pull/1731"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:92cce1f432283a2b533ecc54b8b778cf5a340d5d1e61b11292d8595d81070f6c · sha256:ad159442c3248d0c… · /containers/cna/references/3
{"name":"https://github.com/stellar/rs-soroban-sdk/security/advisories/GHSA-4chv-4c6w-w254","tags":["x_refsource_CONFIRM"],"url":"https://github.com/stellar/rs-soroban-sdk/security/advisories/GHSA-4chv-4c6w-w254"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:92cce1f432283a2b533ecc54b8b778cf5a340d5d1e61b11292d8595d81070f6c · sha256:ad159442c3248d0c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.