Vulnerability Report: GO-2025-3476
- GHSA-x5vx-95h7-rv4p
- Affects: github.com/cosmos/cosmos-sdk
- Published: Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk
For detailed information about this vulnerability, visit https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-x5vx-95h7-rv4p.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.47.16-ics-lsm, from v0.50.0-alpha.0 before v0.50.12
-
before v0.47.16-ics-lsm, from v0.50.0-alpha.0 before v0.50.12
-
before v0.47.16-ics-lsm, from v0.50.0-alpha.0 before v0.50.12
Aliases
References
- https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-x5vx-95h7-rv4p
- https://github.com/cosmos/cosmos-sdk/commit/0a98b65b24900a0e608866c78f172cf8e4140aea
- https://github.com/cosmos/cosmos-sdk/releases/tag/v0.47.16
- https://github.com/cosmos/cosmos-sdk/releases/tag/v0.50.12
- https://vuln.go.dev/ID/GO-2025-3476.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.