Intel

AIKIDO-2025-10040

koin-core is vulnerable to Race Condition

Race Condition Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 24, 2025

10

Low Risk

This Affects:

JAVAkoin-core
3.1.0 - 4.0.1
Fixed in 4.0.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a race condition, in rare cases this causes application crashes, which might be exploited by malicious actors.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

koin-core is vulnerable to Race Condition in versions 3.1.0 - 4.0.1.

How to fix this

Upgrade the io.insert-koin:koin-core library to the patch version.