Vulnerability Report: GO-2024-3244
- CVE-2024-50354, GHSA-cph5-3pgr-c82g
- Affects: github.com/consensys/gnark
- Published: Nov 01, 2024
- Modified: Feb 06, 2025
Gnark out-of-memory during deserialization with crafted inputs in github.com/consensys/gnark
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-cph5-3pgr-c82g.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.12.0
-
before v0.12.0
-
before v0.12.0
-
before v0.12.0
-
before v0.12.0
-
before v0.12.0
-
before v0.12.0
Aliases
References
- https://github.com/advisories/GHSA-cph5-3pgr-c82g
- https://github.com/Consensys/gnark/commit/47ae846339add2bdf9983e499342bfdfe195191d
- https://github.com/Consensys/gnark/pull/1307
- https://vuln.go.dev/ID/GO-2024-3244.json
Credits
- pventuzelo
Feedback
See anything missing or incorrect?
Suggest an edit to this report.