mirror of
				https://github.com/XRPLF/xrpl-dev-portal.git
				synced 2025-11-04 11:55:50 +00:00 
			
		
		
		
	include link to fix and update incident response timeline
This commit is contained in:
		@@ -1,6 +1,6 @@
 | 
			
		||||
---
 | 
			
		||||
category: 2025
 | 
			
		||||
date: "2025-09-26"
 | 
			
		||||
date: "2025-09-29"
 | 
			
		||||
template: '../../@theme/templates/blogpost'
 | 
			
		||||
seo:
 | 
			
		||||
    description: This vulnerability disclosure report contains technical details of the XRP Ledger bug reported on September 15, 2025.
 | 
			
		||||
@@ -98,7 +98,7 @@ If you sign online (via RPC), the invalid signature will be caught early and rej
 | 
			
		||||
 | 
			
		||||
## Fixes / Patches Available
 | 
			
		||||
 | 
			
		||||
We’ve proposed a fix which is under careful review and testing.
 | 
			
		||||
The fix for this issue is available on devnet in an updated version of the feature amendment: `PermissionDelegationV1_1`. You can see the details of the fix [here](https://github.com/XRPLF/rippled/pull/5825). The new amendment replaces `PermissionDelegation` and `DelegateV1_1`, both of which are now deprecated.
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
## Acknowledgements
 | 
			
		||||
@@ -124,5 +124,7 @@ For more information or to report further issues, please contact the team at [bu
 | 
			
		||||
 | 
			
		||||
| Key Actions | Timestamp | Description |
 | 
			
		||||
|-------------|-----------|-------------|
 | 
			
		||||
|**Initial Discovery**    | September 15th, 2025  |Alerted by tequ (a community member) about the vulnerability|
 | 
			
		||||
|**Mitigation Actions Taken**  | September 15th, 2025  | Messaged UNL validators on Mattermost to recommend voting No for PermissionDelegation amendment; Additional UNL validators have since applied vetoes to block the amendment|
 | 
			
		||||
| Initial Discovery    | September 15, 2025  | Alerted by tequ (a community member) about the vulnerability. |
 | 
			
		||||
| Mitigation Actions Taken  | September 15, 2025  | Messaged UNL validators on Mattermost to recommend voting No for `PermissionDelegation` amendment; additional UNL validators have since applied vetoes to block the amendment. |
 | 
			
		||||
| Resolution Completed | September 29, 2025 | The vulnerability has been fixed and made available in an updated amendment: `PermissionDelegationV1_1`. |
 | 
			
		||||
| Report Published | January 10, 2025 | Blog published with details of new feature amendment. |
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user