Vulnerability Report: GO-2024-3339
- GHSA-8wcc-m6j2-qxvm
- Affects: cosmossdk.io/x/tx, github.com/cosmos/cosmos-sdk
- Published: Dec 18, 2024
- Modified: Dec 20, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk
For detailed information about this vulnerability, visit https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-8wcc-m6j2-qxvm.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.13.7
-
before v0.47.15, from v0.50.0-alpha.0 before v0.50.11
1 unexported affected symbols
- interfaceRegistry.UnpackAny
-
before v0.47.15, from v0.50.0-alpha.0 before v0.50.11
Aliases
References
- https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-8wcc-m6j2-qxvm
- https://github.com/cosmos/cosmos-sdk/commit/c6b1bdcd5628e3e425a3f02881d3c7db1d7af653
- https://github.com/cosmos/cosmos-sdk/releases/tag/v0.47.15
- https://github.com/cosmos/cosmos-sdk/releases/tag/v0.50.11
- https://vuln.go.dev/ID/GO-2024-3339.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.