CVE-2026-32322: rs-soroban-sdk: `Fr` scalar field equality comparison bypasses modular reduction
(updated )
Missing modular reduction in Fr causes incorrect equality comparisons for BN254 and BLS12-381 types in soroban-sdk.
References
- github.com/advisories/GHSA-x2hw-px52-wp4m
- github.com/stellar/rs-soroban-sdk
- github.com/stellar/rs-soroban-sdk/commit/082424b30bf22ea7fb8c79f16ccd135e0ae9f3db
- github.com/stellar/rs-soroban-sdk/pull/1750
- github.com/stellar/rs-soroban-sdk/releases/tag/v22.0.11
- github.com/stellar/rs-soroban-sdk/releases/tag/v23.5.3
- github.com/stellar/rs-soroban-sdk/releases/tag/v25.3.0
- github.com/stellar/rs-soroban-sdk/security/advisories/GHSA-x2hw-px52-wp4m
- nvd.nist.gov/vuln/detail/CVE-2026-32322
Code Behaviors & Features
Detect and mitigate CVE-2026-32322 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →