---
id: CVE-2025-59942
title: go-f3 is a Golang implementation of Fast Finality for Filecoin (F3)
summary: >-
  go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In
  versions 0.8.6 and below, go-f3 panics when it validates a "poison" messages
  causing Filecoin nodes consuming F3 messages to become vulnerable. A "poison"
  message ca…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-190
vendor: filecoin
product: go-f3
affected:
  - go-f3 < 0.8.7
patched:
  - go-f3 0.8.7
published: '2025-09-29'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T09:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59942'
references:
  - url: >-
      https://github.com/filecoin-project/go-f3/security/advisories/GHSA-g99p-47x7-mq88
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00335
epssPercentile: 0.24796
ingestedAt: '2026-10-09T09:31:00.994Z'
---

## Overview

go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.6 and below, go-f3 panics when it validates a "poison" messages causing Filecoin nodes consuming F3 messages to become vulnerable. A "poison" message can can cause integer overflow in the signer index validation, which can cause the whole node to crash. These malicious messages aren't self-propagating since the bug is in the validator. An attacker needs to directly send the message to all targets. This issue is fixed in version 0.8.7.

## Affected

- `go-f3 < 0.8.7`

## Remediation

Upgrade past the affected range:

- `go-f3 0.8.7`
