Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/coinbase/x402/go
  4. ›
  5. GHSA-qr2g-p6q7-w82m

GHSA-qr2g-p6q7-w82m: x402 SDK Security Advisory

March 7, 2026

A security vulnerability exists in outdated versions of the x402 SDK.

This vulnerability does not affect users’ private keys, smart contracts, or funds.

The issue impacts resource servers accepting payments on Solana when the facilitator is running a vulnerable version of the x402 SDK.

References

  • github.com/advisories/GHSA-qr2g-p6q7-w82m
  • github.com/coinbase/x402
  • github.com/coinbase/x402/security/advisories/GHSA-qr2g-p6q7-w82m

Code Behaviors & Features

Detect and mitigate GHSA-qr2g-p6q7-w82m with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.5.0

Fixed versions

  • 2.5.0

Solution

Upgrade to version 2.5.0 or above.

Source file

go/github.com/coinbase/x402/go/GHSA-qr2g-p6q7-w82m.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 09 Mar 2026 00:19:53 +0000.