Certik(CSA-2026-001:Tachyon, was disclosed in CometBFT) #652
A critical vulnerability — CSA-2026-001: Tachyon — was disclosed in CometBFT (Advisory: https://github.com/cometbft/cometbft/security/advisories/GHSA-c32p-wcqj-j677).
According to the disclosure, all versions of CometBFT are affected. The issue has been addressed in CometBFT versions v0.38.21 and v0.37.18.
As Gonka is a Cosmos-based project that uses CometBFT, Certik kindly recommends upgrading to a patched version as soon as possible to mitigate potential risks.
💬 Comments (1)
🔄 Auto-synced from Issue #652 every hour.
PR created: https://github.com/gonka-ai/gonka/pull/675
Updates CometBFT to v0.38.21 to fix the Tachyon vulnerability (CSA-2026-001).