Skip to content

Commit b99ba05

Browse files
tatianabgopherbot
authored andcommitted
data/reports: add 2 needs review reports
- data/reports/GO-2025-3448.yaml - data/reports/GO-2025-3449.yaml Updates #3448 Updates #3449 Change-Id: Ia36b7c1627053f98f3c7503729d0a474c4f0f8e8 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/647056 LUCI-TryBot-Result: Go LUCI <[email protected]> Auto-Submit: Tatiana Bradley <[email protected]> Reviewed-by: Damien Neil <[email protected]>
1 parent e20c819 commit b99ba05

File tree

4 files changed

+248
-0
lines changed

4 files changed

+248
-0
lines changed

data/osv/GO-2025-3448.json

Lines changed: 95 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,95 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3448",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"GHSA-23qp-3c2m-xx6w"
8+
],
9+
"summary": "wasmvm: Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm",
10+
"details": "wasmvm: Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm",
11+
"affected": [
12+
{
13+
"package": {
14+
"name": "github.com/CosmWasm/wasmvm",
15+
"ecosystem": "Go"
16+
},
17+
"ranges": [
18+
{
19+
"type": "SEMVER",
20+
"events": [
21+
{
22+
"introduced": "0"
23+
},
24+
{
25+
"fixed": "1.5.8"
26+
}
27+
]
28+
}
29+
],
30+
"ecosystem_specific": {}
31+
},
32+
{
33+
"package": {
34+
"name": "github.com/CosmWasm/wasmvm/v2",
35+
"ecosystem": "Go"
36+
},
37+
"ranges": [
38+
{
39+
"type": "SEMVER",
40+
"events": [
41+
{
42+
"introduced": "2.0.0"
43+
},
44+
{
45+
"fixed": "2.0.6"
46+
},
47+
{
48+
"introduced": "2.1.0"
49+
},
50+
{
51+
"fixed": "2.1.5"
52+
},
53+
{
54+
"introduced": "2.2.0"
55+
},
56+
{
57+
"fixed": "2.2.2"
58+
}
59+
]
60+
}
61+
],
62+
"ecosystem_specific": {}
63+
}
64+
],
65+
"references": [
66+
{
67+
"type": "ADVISORY",
68+
"url": "https://github.com/CosmWasm/wasmvm/security/advisories/GHSA-23qp-3c2m-xx6w"
69+
},
70+
{
71+
"type": "FIX",
72+
"url": "https://github.com/CosmWasm/wasmvm/commit/0aefa4c378457aeb3c07e7975b875be38872c56d"
73+
},
74+
{
75+
"type": "FIX",
76+
"url": "https://github.com/CosmWasm/wasmvm/commit/1151bc6df7d02d1889b8da37cf8510eaf4198eea"
77+
},
78+
{
79+
"type": "FIX",
80+
"url": "https://github.com/CosmWasm/wasmvm/commit/8d44a286fabc793a2fba93752e58cd0fd5b88a2d"
81+
},
82+
{
83+
"type": "FIX",
84+
"url": "https://github.com/CosmWasm/wasmvm/commit/d4ff2adee44e6b9f7415a5dfbb3de745ab9b7678"
85+
},
86+
{
87+
"type": "WEB",
88+
"url": "https://github.com/CosmWasm/advisories/blob/main/CWAs/CWA-2025-001.md"
89+
}
90+
],
91+
"database_specific": {
92+
"url": "https://pkg.go.dev/vuln/GO-2025-3448",
93+
"review_status": "UNREVIEWED"
94+
}
95+
}

data/osv/GO-2025-3449.json

Lines changed: 95 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,95 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3449",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"GHSA-mx2j-7cmv-353c"
8+
],
9+
"summary": "wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm",
10+
"details": "wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm",
11+
"affected": [
12+
{
13+
"package": {
14+
"name": "github.com/CosmWasm/wasmvm",
15+
"ecosystem": "Go"
16+
},
17+
"ranges": [
18+
{
19+
"type": "SEMVER",
20+
"events": [
21+
{
22+
"introduced": "0"
23+
},
24+
{
25+
"fixed": "1.5.8"
26+
}
27+
]
28+
}
29+
],
30+
"ecosystem_specific": {}
31+
},
32+
{
33+
"package": {
34+
"name": "github.com/CosmWasm/wasmvm/v2",
35+
"ecosystem": "Go"
36+
},
37+
"ranges": [
38+
{
39+
"type": "SEMVER",
40+
"events": [
41+
{
42+
"introduced": "2.0.0"
43+
},
44+
{
45+
"fixed": "2.0.6"
46+
},
47+
{
48+
"introduced": "2.1.0"
49+
},
50+
{
51+
"fixed": "2.1.5"
52+
},
53+
{
54+
"introduced": "2.2.0"
55+
},
56+
{
57+
"fixed": "2.2.2"
58+
}
59+
]
60+
}
61+
],
62+
"ecosystem_specific": {}
63+
}
64+
],
65+
"references": [
66+
{
67+
"type": "ADVISORY",
68+
"url": "https://github.com/CosmWasm/wasmvm/security/advisories/GHSA-mx2j-7cmv-353c"
69+
},
70+
{
71+
"type": "WEB",
72+
"url": "https://github.com/CosmWasm/advisories/blob/main/CWAs/CWA-2025-002.md"
73+
},
74+
{
75+
"type": "WEB",
76+
"url": "https://github.com/CosmWasm/cosmwasm/commit/2b7f2faa57a1efc8207455c37f87f1eee6035a27"
77+
},
78+
{
79+
"type": "WEB",
80+
"url": "https://github.com/CosmWasm/cosmwasm/commit/a5d62f65b5eb947ebe40e2085b1c48a9d0a244d0"
81+
},
82+
{
83+
"type": "WEB",
84+
"url": "https://github.com/CosmWasm/cosmwasm/commit/d6143b0aff16a39bbea4be37597d8e9d9b213d3b"
85+
},
86+
{
87+
"type": "WEB",
88+
"url": "https://github.com/CosmWasm/cosmwasm/commit/f0c04c03cbe2557634c1bbcdc2ce203fe7caca58"
89+
}
90+
],
91+
"database_specific": {
92+
"url": "https://pkg.go.dev/vuln/GO-2025-3449",
93+
"review_status": "UNREVIEWED"
94+
}
95+
}

data/reports/GO-2025-3448.yaml

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
id: GO-2025-3448
2+
modules:
3+
- module: github.com/CosmWasm/wasmvm
4+
versions:
5+
- fixed: 1.5.8
6+
vulnerable_at: 1.5.7
7+
- module: github.com/CosmWasm/wasmvm/v2
8+
versions:
9+
- introduced: 2.0.0
10+
- fixed: 2.0.6
11+
- introduced: 2.1.0
12+
- fixed: 2.1.5
13+
- introduced: 2.2.0
14+
- fixed: 2.2.2
15+
vulnerable_at: 2.2.1
16+
summary: 'wasmvm: Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm'
17+
ghsas:
18+
- GHSA-23qp-3c2m-xx6w
19+
references:
20+
- advisory: https://github.com/CosmWasm/wasmvm/security/advisories/GHSA-23qp-3c2m-xx6w
21+
- fix: https://github.com/CosmWasm/wasmvm/commit/0aefa4c378457aeb3c07e7975b875be38872c56d
22+
- fix: https://github.com/CosmWasm/wasmvm/commit/1151bc6df7d02d1889b8da37cf8510eaf4198eea
23+
- fix: https://github.com/CosmWasm/wasmvm/commit/8d44a286fabc793a2fba93752e58cd0fd5b88a2d
24+
- fix: https://github.com/CosmWasm/wasmvm/commit/d4ff2adee44e6b9f7415a5dfbb3de745ab9b7678
25+
- web: https://github.com/CosmWasm/advisories/blob/main/CWAs/CWA-2025-001.md
26+
source:
27+
id: GHSA-23qp-3c2m-xx6w
28+
created: 2025-02-05T18:05:10.210601-05:00
29+
review_status: NEEDS_REVIEW

data/reports/GO-2025-3449.yaml

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
id: GO-2025-3449
2+
modules:
3+
- module: github.com/CosmWasm/wasmvm
4+
versions:
5+
- fixed: 1.5.8
6+
vulnerable_at: 1.5.7
7+
- module: github.com/CosmWasm/wasmvm/v2
8+
versions:
9+
- introduced: 2.0.0
10+
- fixed: 2.0.6
11+
- introduced: 2.1.0
12+
- fixed: 2.1.5
13+
- introduced: 2.2.0
14+
- fixed: 2.2.2
15+
vulnerable_at: 2.2.1
16+
summary: 'wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm'
17+
ghsas:
18+
- GHSA-mx2j-7cmv-353c
19+
references:
20+
- advisory: https://github.com/CosmWasm/wasmvm/security/advisories/GHSA-mx2j-7cmv-353c
21+
- web: https://github.com/CosmWasm/advisories/blob/main/CWAs/CWA-2025-002.md
22+
- web: https://github.com/CosmWasm/cosmwasm/commit/2b7f2faa57a1efc8207455c37f87f1eee6035a27
23+
- web: https://github.com/CosmWasm/cosmwasm/commit/a5d62f65b5eb947ebe40e2085b1c48a9d0a244d0
24+
- web: https://github.com/CosmWasm/cosmwasm/commit/d6143b0aff16a39bbea4be37597d8e9d9b213d3b
25+
- web: https://github.com/CosmWasm/cosmwasm/commit/f0c04c03cbe2557634c1bbcdc2ce203fe7caca58
26+
source:
27+
id: GHSA-mx2j-7cmv-353c
28+
created: 2025-02-05T18:05:06.244469-05:00
29+
review_status: NEEDS_REVIEW

0 commit comments

Comments
 (0)