CVE-2018-14439: Eblock EOS4J

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

espritblock eos4j, an unofficial SDK for EOS, through 2018-07-12 mishandles floating-point numbers with more than four digits after the decimal point, which might allow attackers to trigger currency transfers of unintended amounts.

Affected products

  • Eblock EOS4J: up to and including 2018-07-12

Published 2018-07-20. Last modified 2026-06-17.