CVE-2026-42278Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of SmartTransferTx contains a critical logic flaw in its policy enforcement pipeline. When a transaction originates from a "Pocket" (a derived sub-address documented in the protocol as a way to organize funds), the engine fails to resolve the pocket's parent account before checking the spending policy. Because pockets are "virtual" addresses that exist only as entries in the pocket_to_parent map and do not have their own SmartAccountConfig entries, the check_spending_policy method defaults to an "authorized/no policy" result. This allow any user (or attacker in possession of a parent key) to instantly drain every pocket on an account, even if the parent account has a strict 24-hour vault delay or a 1 UDAG daily limit. This issue has been patched via commit fb6ef59.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-08: 1Mentions · 2026-05-09: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 105-0805-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-42278 UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of SmartTransferTx contains a critical logic flaw i… https://www.cve.org/CVERecord?id=CVE-2026-42278

    Post summary

    The post announces CVE-2026-42278, noting a critical logic flaw in the UltraDAG blockchain's SmartTransferTx implementation prior to commit fb6ef59.

    00010174
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42278 Critical Logic Flaw in UltraDAG StateEngine SmartTransferTx Policy Enforcement https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42278

    Post summary

    The post notes the discovery of CVE‑2026‑42278, describing it as a critical logic flaw in UltraDAG’s policy enforcement, but provides no further technical or remediation details.

    0000036
    4.0K followersView on X

Explore more