File tree 4 files changed +248
-0
lines changed
4 files changed +248
-0
lines changed Original file line number Diff line number Diff line change
1
+ {
2
+ "schema_version" : " 1.3.1" ,
3
+ "id" : " GO-2025-3448" ,
4
+ "modified" : " 0001-01-01T00:00:00Z" ,
5
+ "published" : " 0001-01-01T00:00:00Z" ,
6
+ "aliases" : [
7
+ " GHSA-23qp-3c2m-xx6w"
8
+ ],
9
+ "summary" : " wasmvm: Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm" ,
10
+ "details" : " wasmvm: Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm" ,
11
+ "affected" : [
12
+ {
13
+ "package" : {
14
+ "name" : " github.com/CosmWasm/wasmvm" ,
15
+ "ecosystem" : " Go"
16
+ },
17
+ "ranges" : [
18
+ {
19
+ "type" : " SEMVER" ,
20
+ "events" : [
21
+ {
22
+ "introduced" : " 0"
23
+ },
24
+ {
25
+ "fixed" : " 1.5.8"
26
+ }
27
+ ]
28
+ }
29
+ ],
30
+ "ecosystem_specific" : {}
31
+ },
32
+ {
33
+ "package" : {
34
+ "name" : " github.com/CosmWasm/wasmvm/v2" ,
35
+ "ecosystem" : " Go"
36
+ },
37
+ "ranges" : [
38
+ {
39
+ "type" : " SEMVER" ,
40
+ "events" : [
41
+ {
42
+ "introduced" : " 2.0.0"
43
+ },
44
+ {
45
+ "fixed" : " 2.0.6"
46
+ },
47
+ {
48
+ "introduced" : " 2.1.0"
49
+ },
50
+ {
51
+ "fixed" : " 2.1.5"
52
+ },
53
+ {
54
+ "introduced" : " 2.2.0"
55
+ },
56
+ {
57
+ "fixed" : " 2.2.2"
58
+ }
59
+ ]
60
+ }
61
+ ],
62
+ "ecosystem_specific" : {}
63
+ }
64
+ ],
65
+ "references" : [
66
+ {
67
+ "type" : " ADVISORY" ,
68
+ "url" : " https://github.com/CosmWasm/wasmvm/security/advisories/GHSA-23qp-3c2m-xx6w"
69
+ },
70
+ {
71
+ "type" : " FIX" ,
72
+ "url" : " https://github.com/CosmWasm/wasmvm/commit/0aefa4c378457aeb3c07e7975b875be38872c56d"
73
+ },
74
+ {
75
+ "type" : " FIX" ,
76
+ "url" : " https://github.com/CosmWasm/wasmvm/commit/1151bc6df7d02d1889b8da37cf8510eaf4198eea"
77
+ },
78
+ {
79
+ "type" : " FIX" ,
80
+ "url" : " https://github.com/CosmWasm/wasmvm/commit/8d44a286fabc793a2fba93752e58cd0fd5b88a2d"
81
+ },
82
+ {
83
+ "type" : " FIX" ,
84
+ "url" : " https://github.com/CosmWasm/wasmvm/commit/d4ff2adee44e6b9f7415a5dfbb3de745ab9b7678"
85
+ },
86
+ {
87
+ "type" : " WEB" ,
88
+ "url" : " https://github.com/CosmWasm/advisories/blob/main/CWAs/CWA-2025-001.md"
89
+ }
90
+ ],
91
+ "database_specific" : {
92
+ "url" : " https://pkg.go.dev/vuln/GO-2025-3448" ,
93
+ "review_status" : " UNREVIEWED"
94
+ }
95
+ }
Original file line number Diff line number Diff line change
1
+ {
2
+ "schema_version" : " 1.3.1" ,
3
+ "id" : " GO-2025-3449" ,
4
+ "modified" : " 0001-01-01T00:00:00Z" ,
5
+ "published" : " 0001-01-01T00:00:00Z" ,
6
+ "aliases" : [
7
+ " GHSA-mx2j-7cmv-353c"
8
+ ],
9
+ "summary" : " wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm" ,
10
+ "details" : " wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm" ,
11
+ "affected" : [
12
+ {
13
+ "package" : {
14
+ "name" : " github.com/CosmWasm/wasmvm" ,
15
+ "ecosystem" : " Go"
16
+ },
17
+ "ranges" : [
18
+ {
19
+ "type" : " SEMVER" ,
20
+ "events" : [
21
+ {
22
+ "introduced" : " 0"
23
+ },
24
+ {
25
+ "fixed" : " 1.5.8"
26
+ }
27
+ ]
28
+ }
29
+ ],
30
+ "ecosystem_specific" : {}
31
+ },
32
+ {
33
+ "package" : {
34
+ "name" : " github.com/CosmWasm/wasmvm/v2" ,
35
+ "ecosystem" : " Go"
36
+ },
37
+ "ranges" : [
38
+ {
39
+ "type" : " SEMVER" ,
40
+ "events" : [
41
+ {
42
+ "introduced" : " 2.0.0"
43
+ },
44
+ {
45
+ "fixed" : " 2.0.6"
46
+ },
47
+ {
48
+ "introduced" : " 2.1.0"
49
+ },
50
+ {
51
+ "fixed" : " 2.1.5"
52
+ },
53
+ {
54
+ "introduced" : " 2.2.0"
55
+ },
56
+ {
57
+ "fixed" : " 2.2.2"
58
+ }
59
+ ]
60
+ }
61
+ ],
62
+ "ecosystem_specific" : {}
63
+ }
64
+ ],
65
+ "references" : [
66
+ {
67
+ "type" : " ADVISORY" ,
68
+ "url" : " https://github.com/CosmWasm/wasmvm/security/advisories/GHSA-mx2j-7cmv-353c"
69
+ },
70
+ {
71
+ "type" : " WEB" ,
72
+ "url" : " https://github.com/CosmWasm/advisories/blob/main/CWAs/CWA-2025-002.md"
73
+ },
74
+ {
75
+ "type" : " WEB" ,
76
+ "url" : " https://github.com/CosmWasm/cosmwasm/commit/2b7f2faa57a1efc8207455c37f87f1eee6035a27"
77
+ },
78
+ {
79
+ "type" : " WEB" ,
80
+ "url" : " https://github.com/CosmWasm/cosmwasm/commit/a5d62f65b5eb947ebe40e2085b1c48a9d0a244d0"
81
+ },
82
+ {
83
+ "type" : " WEB" ,
84
+ "url" : " https://github.com/CosmWasm/cosmwasm/commit/d6143b0aff16a39bbea4be37597d8e9d9b213d3b"
85
+ },
86
+ {
87
+ "type" : " WEB" ,
88
+ "url" : " https://github.com/CosmWasm/cosmwasm/commit/f0c04c03cbe2557634c1bbcdc2ce203fe7caca58"
89
+ }
90
+ ],
91
+ "database_specific" : {
92
+ "url" : " https://pkg.go.dev/vuln/GO-2025-3449" ,
93
+ "review_status" : " UNREVIEWED"
94
+ }
95
+ }
Original file line number Diff line number Diff line change
1
+ id : GO-2025-3448
2
+ modules :
3
+ - module : github.com/CosmWasm/wasmvm
4
+ versions :
5
+ - fixed : 1.5.8
6
+ vulnerable_at : 1.5.7
7
+ - module : github.com/CosmWasm/wasmvm/v2
8
+ versions :
9
+ - introduced : 2.0.0
10
+ - fixed : 2.0.6
11
+ - introduced : 2.1.0
12
+ - fixed : 2.1.5
13
+ - introduced : 2.2.0
14
+ - fixed : 2.2.2
15
+ vulnerable_at : 2.2.1
16
+ summary : ' wasmvm: Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm'
17
+ ghsas :
18
+ - GHSA-23qp-3c2m-xx6w
19
+ references :
20
+ - advisory : https://github.com/CosmWasm/wasmvm/security/advisories/GHSA-23qp-3c2m-xx6w
21
+ - fix : https://github.com/CosmWasm/wasmvm/commit/0aefa4c378457aeb3c07e7975b875be38872c56d
22
+ - fix : https://github.com/CosmWasm/wasmvm/commit/1151bc6df7d02d1889b8da37cf8510eaf4198eea
23
+ - fix : https://github.com/CosmWasm/wasmvm/commit/8d44a286fabc793a2fba93752e58cd0fd5b88a2d
24
+ - fix : https://github.com/CosmWasm/wasmvm/commit/d4ff2adee44e6b9f7415a5dfbb3de745ab9b7678
25
+ - web : https://github.com/CosmWasm/advisories/blob/main/CWAs/CWA-2025-001.md
26
+ source :
27
+ id : GHSA-23qp-3c2m-xx6w
28
+ created : 2025-02-05T18:05:10.210601-05:00
29
+ review_status : NEEDS_REVIEW
Original file line number Diff line number Diff line change
1
+ id : GO-2025-3449
2
+ modules :
3
+ - module : github.com/CosmWasm/wasmvm
4
+ versions :
5
+ - fixed : 1.5.8
6
+ vulnerable_at : 1.5.7
7
+ - module : github.com/CosmWasm/wasmvm/v2
8
+ versions :
9
+ - introduced : 2.0.0
10
+ - fixed : 2.0.6
11
+ - introduced : 2.1.0
12
+ - fixed : 2.1.5
13
+ - introduced : 2.2.0
14
+ - fixed : 2.2.2
15
+ vulnerable_at : 2.2.1
16
+ summary : ' wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm'
17
+ ghsas :
18
+ - GHSA-mx2j-7cmv-353c
19
+ references :
20
+ - advisory : https://github.com/CosmWasm/wasmvm/security/advisories/GHSA-mx2j-7cmv-353c
21
+ - web : https://github.com/CosmWasm/advisories/blob/main/CWAs/CWA-2025-002.md
22
+ - web : https://github.com/CosmWasm/cosmwasm/commit/2b7f2faa57a1efc8207455c37f87f1eee6035a27
23
+ - web : https://github.com/CosmWasm/cosmwasm/commit/a5d62f65b5eb947ebe40e2085b1c48a9d0a244d0
24
+ - web : https://github.com/CosmWasm/cosmwasm/commit/d6143b0aff16a39bbea4be37597d8e9d9b213d3b
25
+ - web : https://github.com/CosmWasm/cosmwasm/commit/f0c04c03cbe2557634c1bbcdc2ce203fe7caca58
26
+ source :
27
+ id : GHSA-mx2j-7cmv-353c
28
+ created : 2025-02-05T18:05:06.244469-05:00
29
+ review_status : NEEDS_REVIEW
You can’t perform that action at this time.
0 commit comments