Skip to content

x/vulndb: potential Go vuln in github.com/cometbft/cometbft: CVE-2025-24371 #3446

Closed as not planned
@GoVulnBot

Description

@GoVulnBot

Advisory CVE-2025-24371 references a vulnerability in the following Go modules:

Module
github.com/cometbft/cometbft

Description:
CometBFT is a distributed, Byzantine fault-tolerant, deterministic state machine replication engine. In the blocksync protocol peers send their base and latest heights when they connect to a new node (A), which is syncing to the tip of a network. base acts as a lower ground and informs A that the peer only has blocks starting from height base. latest height informs A about the latest block in a network. Normally, nodes would only report increasing heights. If B fails to provide the latest block, B is removed and the latest height (target height) is recalculated based on...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/cometbft/cometbft
      vulnerable_at: 1.0.1
summary: CVE-2025-24371 in github.com/cometbft/cometbft
cves:
    - CVE-2025-24371
references:
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-24371
    - web: https://github.com/cometbft/cometbft/releases/tag/v0.38.17
    - web: https://github.com/cometbft/cometbft/releases/tag/v1.0.1
    - web: https://github.com/cometbft/cometbft/security/advisories/GHSA-22qq-3xwm-r5x4
source:
    id: CVE-2025-24371
    created: 2025-02-03T23:01:32.087082518Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions