CVE-2026-45581
📛 CVE Title
(no title)
Description
fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- medium
- CVSS score
- 5.5 / 10
- CVSS vector
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N- Effective score
- 5.5 / 10 MEDIUM source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-45581
NVD / KEV / EPSS data refreshed 2026-05-25 00:13 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-35139 - Assigner
- GitHub_M
- Published
- Jun 8, 2026, 4:53:45 PM
- Updated
- Jun 9, 2026, 3:51:04 PM
- EUVD base score (CVSS 3.1)
-
5.5 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - EUVD-reported EPSS
- 0.1100
- Vendors
- Hyperledger
- Products
-
fabric-chaincode-java (2.3.1, < 2.5.10)
- Aliases
-
GHSA-wg5x-3g47-v38r
ENISA description: fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An attacker with access to the chaincode server logs could recover the TLS private key password. If the attacker can also obtain the TLS private key, they could impersonate the chaincode server. This issue has been patched in version 2.5.10.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (3)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://github.com/hyperledger/fabric-chaincode-java/security/advisories/GHSA-wg5x-3g47-v38r tenable:github.com
- https://nvd.nist.gov/vuln/detail/CVE-2026-45581 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45581 tenable:www.cve.org
Remediations (10)
-
web:api.msrc.microsoft.com
The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices.\n \nWe are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. \n\n**Mitigation FAQs**\n\n**Should I leverage the temporary ...
2026-05-26 03:08 UTC -
web:aviatrix.ai
Microsoft addresses the YellowKey vulnerability ( CVE - 2026 -45585) that allows physical bypass of BitLocker encryption in Windows 11 and Server 2025.
2026-05-26 03:08 UTC -
web:cyberpress.org
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two actively exploited Microsoft Defender vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, issuing an urgent remediation directive for federal agencies with a due date of June 3, 2026 .
2026-05-26 03:08 UTC -
web:cybersecuritynews.com
No patch has been released yet; Microsoft has instead issued a multi-step manual mitigation guide while a formal security update is prepared. Windows BitLocker Security Bypass The vulnerability originates in WinRE's handling of the BootExecute registry value under HKLM\ControlSet001\Control\Session Manager.
2026-05-26 03:08 UTC -
web:github.com
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available ...
2026-05-26 03:08 UTC -
web:jamesvincent.co.uk
On the 19th of May, Microsoft released a mitigation guide for the Windows BitLocker Security Feature Bypass Vulnerability, dubbed YellowKey. YellowKey ( CVE - 2026 -45585) is a Windows BitLocker bypass vulnerability that abuses the Windows Recovery Environment (WinRE) to grant an attacker with physical access unauthorised access to encrypted drives ...
2026-05-26 03:08 UTC -
web:m365admin.handsontek.net
Microsoft has updated the mitigation guidance in CVE - 2026 -45585, a Windows BitLocker security feature bypass vulnerability. The updated guidance replaces previously documented manual mitigation steps with a script that helps reduce exposure while a future security update is developed to address this vulnerability. Note that a limited set of Windows versions are affected: Windows 11, versions ...
2026-05-26 03:08 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-05-26 03:08 UTC -
web:securityarsenal.com
Microsoft releases mitigation for CVE - 2026 -45585 (YellowKey). Defenders must act now to block BitLocker bypass risks on Windows.
2026-05-26 03:08 UTC -
web:www.securityweek.com
Microsoft has announced mitigations for CVE - 2026 -45585, a BitLocker bypass triggered via FsTx in Windows Recovery.
2026-05-26 03:08 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.