{"id":"CVE-2023-42806","summary":"Snapshot signature not including HeadID will allow replay attacks","details":"Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\\mathsf{cid}$` allows an attacker (which must be a participant of this head) to use a snapshot from an old head instance with the same participants to close the head or contest the state with it. This can lead to an incorrect distribution of value (= value extraction attack; hard, but possible) or prevent the head to finalize because the value available is not consistent with the closed utxo state (= denial of service; easy). A patch is planned for version 0.13.0. As a workaround, rotate keys between heads so not to re-use keys and not result in the same multi-signature participants.","aliases":["GHSA-gr36-mc6v-72qq"],"modified":"2026-08-27T03:57:58.574427636Z","published":"2023-09-21T16:45:34.742Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/42xxx/CVE-2023-42806.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-347"]},"references":[{"type":"WEB","url":"https://github.com/input-output-hk/hydra/blob/ec6c7a2ab651462228475d0b34264e9a182c22bb/hydra-node/src/Hydra/HeadLogic.hs#L357"},{"type":"WEB","url":"https://github.com/input-output-hk/hydra/blob/ec6c7a2ab651462228475d0b34264e9a182c22bb/hydra-node/src/Hydra/Snapshot.hs#L50-L54"},{"type":"WEB","url":"https://github.com/input-output-hk/hydra/blob/ec6c7a2ab651462228475d0b34264e9a182c22bb/hydra-plutus/src/Hydra/Contract/Head.hs#L583-L599"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/42xxx/CVE-2023-42806.json"},{"type":"ADVISORY","url":"https://github.com/input-output-hk/hydra/security/advisories/GHSA-gr36-mc6v-72qq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-42806"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cardano-scaling/hydra","events":[{"introduced":"0"},{"fixed":"9f1027e0fdff6765f5233f19c4639fdaa3558bfa"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:iohk:hydra:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.13.0"}]}}],"versions":["0.12.0","0.11.0","0.10.0","0.9.0","0.8.1","0.8.0","0.7.0","0.6.0","0.5.0","0.4.0","plutus-merkle-tree-1.0.0","plutus-cbor-1.0.0","0.3.0","0.2.0","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-42806.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"}]}