{"id":"GHSA-c32p-wcqj-j677","summary":"CometBFT has inconsistencies between how commit signatures are verified and how block time is derived","details":"# CSA-2026-001: Tachyon\n\n## Description\n\n**Name:** CSA-2026-001: Tachyon\n\n**Criticality:** Critical (Catastrophic Impact; Possible Likelihood per [ACMv1.2](https://github.com/interchainio/security/blob/main/resources/CLASSIFICATION_MATRIX.md))\n\n**Affected versions:** All versions of CometBFT\n\n**Affected users:** Validators and protocols relying on block timestamps\n\n## Description\n\nA consensus-level vulnerability was discovered in CometBFT's \"BFT Time\" implementation due to an inconsistency between how commit signatures are verified and how block time is derived.\n\nThis breaks a core BFT Time guarantee: \"A faulty process cannot arbitrarily increase the Time value.\"\n\n## Impact\n\nDownstream impact on chains affects any module, smart contract, or system that relies on the block timestamp.\n\n## Patches\n\nThe new CometBFT releases [v0.38.21](https://github.com/cometbft/cometbft/releases/tag/v0.38.21) and [v0.37.18](https://github.com/cometbft/cometbft/releases/tag/v0.37.18) fix this issue. The `main` unreleased branch is also patched.\n\n## Workarounds\n\nThere are no effective workarounds for this vulnerability. Upgrading to patched versions is required.\n\n## Timeline\n\n- January 8, 2026, 5:27PM UTC: Issue reported to Cosmos Bug Bounty Program\n- January 9, 2026, 4:55AM UTC: Issue triaged and validated by core team\n- January 12, 2026, 10:25PM UTC: Core team completes patch for the issue\n- January 13, 2026 4:41PM UTC: Pre-notification delivered to ecosystem partners\n- January 23, 2026, 3:00PM UTC: Patch made available\n\n## Credits\n\nThis issue was reported to the Cosmos Bug Bounty Program on HackerOne. Credit to SEAL 911 and [QED Audit](https://x.com/QED_Audit) for the discovery and help with the patch.\n\nIf you believe you have found a bug in the Cosmos Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos.\n\nIf you have questions about Cosmos security efforts, please reach out to our official communication channel at security@cosmoslabs.io.\n\nA Github Security Advisory for this issue is available in the CometBFT repository. For more information about CometBFT, see https://docs.cometbft.com/.","aliases":["GO-2026-4361"],"modified":"2026-02-28T05:13:47.205461Z","published":"2026-01-23T16:56:23Z","database_specific":{"cwe_ids":["CWE-703"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-01-23T16:56:23Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/cometbft/cometbft/security/advisories/GHSA-c32p-wcqj-j677"},{"type":"WEB","url":"https://github.com/cometbft/cometbft/commit/bf8274fcdbcab2bc652660ae627196a90a6efb97"},{"type":"PACKAGE","url":"https://github.com/cometbft/cometbft"},{"type":"WEB","url":"https://github.com/cometbft/cometbft/releases/tag/v0.37.18"},{"type":"WEB","url":"https://github.com/cometbft/cometbft/releases/tag/v0.38.21"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2026-4361"}],"affected":[{"package":{"name":"github.com/cometbft/cometbft","ecosystem":"Go","purl":"pkg:golang/github.com/cometbft/cometbft"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.38.0-alpha.1"},{"fixed":"0.38.21"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.38.20","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-c32p-wcqj-j677/GHSA-c32p-wcqj-j677.json"}},{"package":{"name":"github.com/cometbft/cometbft","ecosystem":"Go","purl":"pkg:golang/github.com/cometbft/cometbft"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.37.18"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.37.17","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-c32p-wcqj-j677/GHSA-c32p-wcqj-j677.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}