Contact security@openvm.dev.
Security: openvm-org/openvm
Security
SECURITY.md
-
OpenVmHalo2Verifier accepts non-canonical app commitmentsGHSA-w82q-w67c-67wv published
Jun 26, 2026 by shuklaayushModerate -
OpenVmHalo2Verifier self-call can bypass proof verificationGHSA-j29p-wr24-hp4f published
Jun 26, 2026 by shuklaayushCritical -
MemoryMerkleAir allows below-leaf rows to alter memory rootsGHSA-396x-v8w4-9x82 published
Jun 26, 2026 by shuklaayushCritical -
`openvm-pairing` pairing check missing proper subfield check on scaling factorGHSA-76mq-v757-53gr published
May 15, 2026 by jpw-axiomCritical -
SHA-256 and Keccak circuits under-constrainedGHSA-9jfx-4f4f-497j published
May 15, 2026 by jpw-axiomHigh -
Native recursion verifier missing constraints in program and circuitGHSA-j9m2-fxc5-fr82 published
May 15, 2026 by jpw-axiomCritical -
System AIRs missing boolean or zero assertionsGHSA-fh29-29h9-qm9h published
May 15, 2026 by jpw-axiomCritical -
Plonky3 missing final polynomial degree check and randomness in FRI verifierGHSA-4w7p-8f9q-f4g2 published
Jun 3, 2025 by jonathanpwangHigh -
Byte decomposition of pc in AUIPC chip can overflowGHSA-jf2r-x3j4-23m7 published
May 2, 2025 by jonathanpwangHigh
Learn more about advisories related to openvm-org/openvm in the GitHub Advisory Database