Disclosure summary
go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.8 and below, go-f3's justification verification caching mechanism has a vulnerability where verification results are cached without properly considering the context of the message. An attacker can bypass justification verification by submitting a valid message with a correct justification and then reusing the same cached justification in contexts where it would normally be invalid. This occurs because the cached verification does not properly validate the relationship between the justification and the specific message context it's being used with. This issue is fixed in version 0.8.9.
Source-reported weakness categories
CWE-305
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2025-59941
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| filecoin | go-f3 | * {"versionEndExcluding":"0.8.9"} |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Patch
- github.com — Vendor Advisory
PUBLISHED 2025-09-29T19:15:32-04:00
MODIFIED 2026-10-09T05:10:00-04:00
INGESTED 2026-10-10T20:50:24-04:00