go-f3 vulnerabilities
CVEs whose affected-version data names the go-f3 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-59942High· 7.5go-f3 is a Golang implementation of Fast Finality for Filecoin (F3)
go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.6 and below, go-f3 panics when it validates a "poison" messages causing Filecoin nodes consuming F3 messages to become vulnerable. A "poison" message ca…
▾ Twilightfilecoin · go-f3EPSS 0.34%via NVD
CVE-2025-59941Medium· 5.9go-f3 is a Golang implementation of Fast Finality for Filecoin (F3)
go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.8 and below, go-f3's justification verification caching mechanism has a vulnerability where verification results are cached without properly considering…
▾ Sunlitfilecoin · go-f3EPSS 0.24%via NVD