VYPR

Bifrost

by Xbifrost

CVEs (3)

  • CVE-2026-86840CriSep 8, 2026
    risk 0.59cvss 9.1epss 0.00

    The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on…

  • CVE-2022-39219HigSep 26, 2022
    risk 0.55cvss 8.5epss 0.01

    Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow group members who only have read permissions…

  • CVE-2022-39267HigOct 19, 2022
    risk 0.50cvss 8.8epss 0.01

    Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis, MongoDB, ClickHouse, MySQL and other services for production environments. Versions prior to 1.8.8-release are subject to authentication bypass in the admin and monitor user groups by deleting the…