CVE-2026-26267Disclosure(stellar / rs-soroban-sdk)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch stellar rs-soroban-sdk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` macro contains a bug in how it wires up function calls. `#[contractimpl]` generates code that uses `MyContract::value()` style calls even when it's processing the trait version. This means if an inherent function is also defined with the same name, the inherent function gets called instead of the trait function. This means the Wasm-exported entry point silently calls the wrong function when two conditions are met simultaneously: First, an `impl Trait for MyContract` block is defined with one or more functions, with `#[contractimpl]` applied. Second, an `impl MyContract` block is defined with one or more identically named functions, without `#[contractimpl]` applied. If the trait version contains important security checks, such as verifying the caller is authorized, that the inherent version does not, those checks are bypassed. Anyone interacting with the contract through its public interface will call the wrong function. The problem is patched in `soroban-sdk-macros` versions 22.0.10, 23.5.2, and 25.1.1. The fix changes the generated call from `<Type>::func()` to `<Type as Trait>::func()` when processing trait implementations, ensuring Rust resolves to the trait associated function regardless of whether an inherent function with the same name exists. Users should upgrade to `soroban-sdk-macros` 22.0.10, 23.5.2, or 25.1.1 and recompile their contracts. If upgrading is not immediately possible, contract developers can avoid the issue by ensuring that no inherent associated function on the contract type shares a name with any function in the trait implementation. Renaming or removing the conflicting inherent function eliminates the ambiguity and causes the macro-generated code to correctly resolve to the trait function.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-670

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rs-soroban-sdk

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-20); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
rs-soroban-sdk

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-20: 1Mentions · 2026-05-18: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-05-18: 1Technical Details · 2026-02-20: 1Technical Details · 2026-05-18: 102-2005-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Rexxx@babp00
    Disclosure

    最近我测试了 @SushiSwap SushiSwap V3 Factory 在 Stellar 主网的合约,发现了个比较要紧的漏洞。 这个漏洞对应 CVE-2026-26267,问题出在 soroban-sdk 23.0.0 到 23.5.1 版本的 #[contractimpl] 宏上。简单来说,合约里如果同时有带权限检查的 trait 方法,和一个同名的普通方法,系统生成的 WASM 会跑到那个没做权限检查的方法上,导致权限检查被绕过。 Sushi 的 Factory 合约地址是 CD3KRKGDRVWPXVB3VXLUMQKMX6XZ6Q2H334IVZD4XXNAMKSRVQL5GLYF,用的是 23.0.2 这个有问题的版本。 我用 Stellar 的 soroban-rpc 做模拟交易测试,随便拿个不是 owner 的地址去调管理员函数,结果 set_owner 换 owner、改协议费、冻结升级、甚至永久禁用升级这些操作,全都能模拟成功,没有出现未授权的错误。 攻击成本很低,大概只要 10 XLM 左右的交易费,就能直接把factory的所有权拿过来,然后想怎么操作就怎么操作。协议现在 TVL 大概 195 万美元,升级也没冻结,风险不小。 建议 Sushi 团队尽快用 23.5.2 及以上版本重新编译部署,同时让当前 owner 先把升级冻结上(set_upgrade_frozen(true)),避免出问题。 这个漏洞用模拟交易就能提前发现,希望相关团队快点处理,也提醒大家在 Stellar 上部署合约的时候,注意 SDK 版本更新。 合约在 Sushi 官方文档里有记录,有兴趣的可以自己去查 #Stellar #Soroban #SushiSwap

    Post summary

    The author discloses a privilege‑bypass flaw in SushiSwap’s Factory contract on Stellar caused by a soroban‑sdk macro bug, allowing non‑owners to execute admin functions; they advise upgrading to 23.5.2+ and freezing upgrades.

    0000032
    669 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26267 soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` macro contains a bug in how it wires up function… https://www.cve.org/CVERecord?id=CVE-2026-26267

    Post summary

    The text announces a CVE affecting the soroban-sdk Rust SDK, specifying a bug in the `#[contractimpl]` macro and indicating the versions that contain the fix, but provides no evidence of exploitation or a PoC.

    00000663
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstellarrs-soroban-sdk-rust-

Explore more