Vulnerability Report: GO-2024-3339
- GHSA-8wcc-m6j2-qxvm
- Affects: github.com/cosmos/cosmos-sdk
- Published: Dec 18, 2024
- Unreviewed
ASA-2024-0012, ASA-2024-0013: CosmosSDK: Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk
For detailed information about this vulnerability, visit https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-8wcc-m6j2-qxvm.
Affected Modules
-
PathGo Versions
-
before v0.47.15, from v0.50.0-alpha.0 before v0.50.11
Aliases
References
- https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-8wcc-m6j2-qxvm
- https://github.com/cosmos/cosmos-sdk/commit/c6b1bdcd5628e3e425a3f02881d3c7db1d7af653
- https://github.com/cosmos/cosmos-sdk/releases/tag/v0.47.15
- https://github.com/cosmos/cosmos-sdk/releases/tag/v0.50.11
- https://vuln.go.dev/ID/GO-2024-3339.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.