CVE-2026-32129General

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

soroban-poseidon provides Poseidon and Poseidon2 cryptographic hash functions for Soroban smart contracts. Poseidon V1 (PoseidonSponge) accepts variable-length inputs without injective padding. When a caller provides fewer inputs than the sponge rate (inputs.len() < T - 1), unused rate positions are implicitly zero-filled. This allows trivial hash collisions: for any input vector [m1, ..., mk] hashed with a sponge of rate > k, hash([m1, ..., mk]) equals hash([m1, ..., mk, 0]) because both produce identical pre-permutation states. This affects any use of PoseidonSponge or poseidon_hash where the number of inputs is less than T - 1 (e.g., hashing 1 input with T=3). Poseidon2 (Poseidon2Sponge) is not affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-328

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-12); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-07-16: 1Technical Details · 2026-03-13: 103-1203-1307-16
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-121
General1
2026-03-131
Disclosure1
2026-07-161
General1
Full discourse3 posts
  • Satish Jalan@SatishJalan52
    General

    @mesayanroy @ahirgrinds @Ashishrd06 @Roan0i @singhsach1 @notarkoroy @CancelSamya @AnindhaBiswas @Vayylstellar I almost shipped Poseidon V1 from circomlib simply because it was the default. Then I came across CVE-2026-32129. That sent me down a rabbit hole, and I ended up switching to Poseidon2. One paper probably saved me from shipping a known vulnerability. Read the CVEs. Always.

    Post summary

    The user mentions encountering CVE-2026-32129 and switching to a newer Poseidon version, but provides no further details about exploitation, patches, or vulnerability specifics.

    20040134
    150 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32129 Hash Collision Vulnerability in Soroban-Poseidon PoseidonSponge Cryptographic Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32129

    Post summary

    This entry references CVE-2026-32129 as a hash collision vulnerability affecting the Soroban-Poseidon PoseidonSponge cryptographic function, providing a link to details but lacking information on PoCs, exploits, patches, or active use.

    0000051
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32129 soroban-poseidon provides Poseidon and Poseidon2 cryptographic hash functions for Soroban smart contracts. Poseidon V1 (PoseidonSponge) accepts variable-length inputs… https://www.cve.org/CVERecord?id=CVE-2026-32129

    Post summary

    The text offers only a brief description of the CVE and links to the CVE record, with no indications of exploits, patches, or clear technical details.

    00000142
    56.7K followersView on X

Explore more