{"id":"CVE-2022-29077","details":"A heap-based buffer overflow exists in rippled before 1.8.5. The vulnerability allows attackers to cause a crash or execute commands remotely on a rippled node, which may lead to XRPL mainnet DoS or compromise. This exposes all digital assets on the XRPL to a security threat.","modified":"2026-08-27T08:40:49.856099Z","published":"2022-04-25T02:59:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29077.json"},"references":[{"type":"WEB","url":"https://github.com/ripple/rippled/compare/1.8.4...1.8.5"},{"type":"WEB","url":"https://ripple.com/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29077.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-29077"},{"type":"ARTICLE","url":"https://xrpl.org/blog/2022/rippled-1.8.5.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/XRPLF/rippled","events":[{"introduced":"0"},{"fixed":"72377e7bf25c4eaee5174186d2db3c6b4210946f"}],"database_specific":{"cpe":"cpe:2.3:a:ripple:rippled:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.8.5"}],"source":["DESCRIPTION","CPE_RANGE"]}}],"versions":["1.8.4","1.8.3","1.8.2","1.8.1","1.7.0","1.6.0","1.5.0","1.4.0","1.3.1","1.3.0","1.2.2","1.2.1","1.2.0","1.1.0","1.0.0","0.90.0","0.80.1","0.80.0","0.70.2","0.70.1","0.70.0","0.60.0","0.50.2","0.50.0","0.50.0-rc2","0.50.0-rc1","0.40.0","0.32.1","0.32.0","0.30.1-rc1","0.30.0-rc1","0.29.1-rc1","0.28.1","0.28.1-rc2","0.28.1-rc1","0.27.0","0.26.0","0.25.1","0.25.0","0.24.0","0.23.0","0.22.0","0.21.0","0.20.1","0.20.0","0.19.2","0.19.1","0.17.0","0.16.0","0.15.0","0.14.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29077.json","vanir_signatures_modified":"2026-08-27T08:40:49Z","vanir_signatures":[{"digest":{"line_hashes":["210707397357993739812613116987614333685","307464896027562437958032019526306783295","296022353296152264758262536646395275237","199657875885241300211392053013559564544"],"threshold":0.9},"id":"CVE-2022-29077-2b1d4fb0","signature_type":"Line","signature_version":"v1","source":"https://github.com/XRPLF/rippled/commit/72377e7bf25c4eaee5174186d2db3c6b4210946f","target":{"file":"src/ripple/protocol/impl/BuildInfo.cpp"},"deprecated":false}]}}],"schema_version":"1.9.0"}