CVE-2026-26267 Details
Description
soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` macro contains a bug in how it wires up function calls. `#[contractimpl]` generates code that uses `MyContract::value()` style calls even when it's processing the trait version. This means if an inherent function is also defined with the same name, the inherent function gets called instead of the trait function. This means the Wasm-exported entry point silently calls the wrong function when two conditions are met simultaneously: First, an `impl Trait for MyContract` block is defined with one or more functions, with `#[contractimpl]` applied. Second, an `impl MyContract` block is defined with one or more identically named functions, without `#[contractimpl]` applied. If the trait version contains important security checks, such as verifying the caller is authorized, that the inherent version does not, those checks are bypassed. Anyone interacting with the contract through its public interface will call the wrong function. The problem is patched in `soroban-sdk-macros` versions 22.0.10, 23.5.2, and 25.1.1. The fix changes the generated call from `<Type>::func()` to `<Type as Trait>::func()` when processing trait implementations, ensuring Rust resolves to the trait associated function regardless of whether an inherent function with the same name exists. Users should upgrade to `soroban-sdk-macros` 22.0.10, 23.5.2, or 25.1.1 and recompile their contracts. If upgrading is not immediately possible, contract developers can avoid the issue by ensuring that no inherent associated function on the contract type shares a name with any function in the trait implementation. Renaming or removing the conflicting inherent function eliminates the ambiguity and causes the macro-generated code to correctly resolve to the trait function.
A vulnerability exists in the Soroban SDK Rust library for Soroban contracts, specifically in versions prior to 22.0.10, 23.5.2, and 25.1.1. The issue arises within the `#[contractimpl]` macro, which incorrectly manages function call resolutions. Instead of properly referencing trait functions, it defaults to inherent functions when names overlap. This misalignment can cause critical security checks, embedded in the trait functions, to be bypassed, potentially leading to unauthorized actions within the contract. The vulnerability is particularly concerning when a contract implements a trait and also defines inherent functions with identical names, as the macro-generated WebAssembly export will inadvertently call the wrong function, omitting essential security verifications.
Users should upgrade to `soroban-sdk-macros` versions 22.0.10, 23.5.2, or 25.1.1 and recompile their contracts. If an immediate upgrade is not possible, contract developers can rename or remove the conflicting inherent function to avoid the issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/stellar/rs-soroban-sdk/commit/e92a3933e5f92dc09da3c740cf6a360d55709a2b | [email protected] | Patch |
| https://github.com/stellar/rs-soroban-sdk/pull/1729 | [email protected] | Issue TrackingPatch |
| https://github.com/stellar/rs-soroban-sdk/pull/1730 | [email protected] | Issue TrackingPatch |
| https://github.com/stellar/rs-soroban-sdk/pull/1731 | [email protected] | Issue TrackingPatch |
| https://github.com/stellar/rs-soroban-sdk/security/advisories/GHSA-4chv-4c6w-w254 | [email protected] | ExploitPatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-670 | Always-Incorrect Control Flow Implementation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| stellar rs-soroban-sdk | < 22.0.10 >= 23.0.0, < 23.5.2 >= 25.0.0, < 25.1.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 20, 2026 | Initial Analysis | [email protected] |
| Feb 19, 2026 | New CVE Received | [email protected] |