CVE-2026-40583Disclosure(ultradag / ultradag)

LOWCVSS 8.2 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance prechecks, but fails authorization only after state mutation has already occurred.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-460CWE-696

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ultradag

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-19); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
ultradag

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-19: 2Mentions · 2026-04-27: 2PoC Mentioned / Linked · 2026-04-19: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-27: 204-1904-27
Signal classification3 categories
Disclosure
250.0%
PoC
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-192
Disclosure1PoC1
2026-04-272
Disclosure1General1
Full discourse4 posts
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    Disclosure

    How I Crashed a Blockchain Node with a Single Vote (CVE-2026–40583) https://medium.com/@sumitshahorg/how-i-crashed-a-blockchain-node-with-a-single-vote-cve-2026-40583-b6dc61d44033?source=rss------bug_bounty-5 #bugbounty #bugbountytips #bugbountytip

    Post summary

    The text only references a Medium article announcing CVE‑2026‑40583, with no explicit PoC, exploitation details, patches, or evidence of active attacks.

    00030542
    40.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40583 UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, a… https://www.cve.org/CVERecord?id=CVE-2026-40583

    Post summary

    The text briefly outlines a vulnerability in UltraDAG’s SmartOp::Vote handling, but does not detail exploits, patches, or active attacks.

    00010158
    57.3K followersView on X
  • HackSage@RealHackSage
    PoC

    🔥 Just dropped a new case study! How I crashed a Layer 1 blockchain node with a single vote. Total impact: Critical | Bounty: 15,000 on chain coin | CVE: CVE-2026-40583 https://medium.com/@sumitshahorg/how-i-crashed-a-blockchain-node-with-a-single-vote-cve-2026-40583-b6dc61d44033 #CyberSecurity #BugBounty #Web3‌‌ https://t.co/fmuLEcDO3R

    Post summary

    The post reveals CVE-2026-40583 and details a proof‑of‑concept crash of a Layer 1 blockchain node via a single vote, but lacks evidence of active exploitation, a formal patch, or a dedicated exploit tool.

    00010149
    11 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40583 UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, a… https://www.cve.org/CVERecord?id=CVE-2026-40583 ----- Traducción: CVE-2026-40583 Ult… http://infoflow.cloud`

    Post summary

    The entry announces CVE‑2026‑40583 against UltraDAG, noting an authorization flaw that lets attackers submit valid vote transactions, but it contains no sign of active exploitation, patching, or a PoC.

    0000044
    72 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appultradagultradag0.1.0--

Explore more