cosmwasm-vm
WebAssembly Smart Contracts for the Cosmos SDK
Activity
- Latest release
- 4w ago
- Total releases
- 211
- Cadence
- ~daily
- Last 12 months
- 27
Reach
- Downloads
- 641.6k
- Stars
- 1.1k
Details
- License
- Apache-2.0
- First release
- Oct 08, 2019
| Version | Released | |
|---|---|---|
3.1.0-rc.1
pre
|
3.1.0-rc.1
pre
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
2.2.9
unknown
|
2.2.9
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
3.0.9
unknown
|
3.0.9
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
2.3.4
unknown
|
2.3.4
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
3.0.8
unknown
|
3.0.8
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
3.1.0-rc.0
unknown
|
3.1.0-rc.0
unknown
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
3.0.7
unknown
|
3.0.7
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
3.0.6
unknown
|
3.0.6
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
2.3.3
unknown
|
2.3.3
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
2.2.8
unknown
|
2.2.8
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
3.0.5
unknown
|
3.0.5
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
3.0.5-rc.0
unknown
|
3.0.5-rc.0
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
3.0.4
unknown
|
3.0.4
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
2.3.2
unknown
|
2.3.2
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
2.2.7
unknown
|
2.2.7
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
3.0.4-rc.0
unknown
|
3.0.4-rc.0
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
2.3.2-rc.0
unknown
|
2.3.2-rc.0
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
2.2.7-rc.1
unknown
|
2.2.7-rc.1
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
2.2.7-rc.0
unknown
|
2.2.7-rc.0
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
3.0.3
unknown
|
3.0.3
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
2.3.1
unknown
|
2.3.1
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
2.2.6
unknown
|
2.2.6
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
2.2.5
unknown
yanked
|
2.2.5
unknown
yanked
Dependencies (36)
+ 28 more
Changelog
Compare changes
|
|
2.2.4
unknown
yanked
|
2.2.4
unknown
yanked
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
2.2.4-rc.0
unknown
yanked
|
2.2.4-rc.0
unknown
yanked
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
2.2.3
unknown
|
2.2.3
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
2.3.0
unknown
|
2.3.0
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
3.0.2
unknown
|
3.0.2
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
3.0.1
unknown
|
3.0.1
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
3.0.0
unknown
|
3.0.0
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
3.0.0-rc.1
unknown
|
3.0.0-rc.1
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
3.0.0-rc.0
unknown
|
3.0.0-rc.0
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
3.0.0-ibc2.0
unknown
|
3.0.0-ibc2.0
unknown
Dependencies (33)
+ 25 more
Changelog
Compare changes
|
|
1.5.11
unknown
|
1.5.11
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
2.1.7
unknown
|
2.1.7
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
2.2.2
unknown
|
2.2.2
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
2.0.9
unknown
|
2.0.9
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
2.1.6
unknown
|
2.1.6
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
2.2.1
unknown
|
2.2.1
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
1.5.10
unknown
|
1.5.10
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
2.2.0
unknown
1 CVE
GHSA-mx2j-7cmv-353c
GO-2025-3449
Feb 04, 2025
wasmvm: Malicious smart contract can slow down block production
Medium
CWA-2025-002Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bugThe vulnerability can be used to slow down block production. The attack requires a malicious contract, so permissioned chains are unlikely to be affected. (We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1.2: https://github.com/interchainio/security/blob/0295254e8645301ccb606d46108a45cede0a73e0/resources/CLASSIFICATION_MATRIX.md Affected versions
2.2.0
Fixed in
1.5.10
2.0.9
2.1.6
2.2.1
References
Updated Jul 09, 2025 · Source: OSV.dev |
2.2.0
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
1.5.9
unknown
1 CVE
GHSA-mx2j-7cmv-353c
GO-2025-3449
Feb 04, 2025
wasmvm: Malicious smart contract can slow down block production
Medium
CWA-2025-002Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bugThe vulnerability can be used to slow down block production. The attack requires a malicious contract, so permissioned chains are unlikely to be affected. (We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1.2: https://github.com/interchainio/security/blob/0295254e8645301ccb606d46108a45cede0a73e0/resources/CLASSIFICATION_MATRIX.md Affected versions
2.2.0
Fixed in
1.5.10
2.0.9
2.1.6
2.2.1
References
Updated Jul 09, 2025 · Source: OSV.dev |
1.5.9
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
2.0.8
unknown
1 CVE
GHSA-mx2j-7cmv-353c
GO-2025-3449
Feb 04, 2025
wasmvm: Malicious smart contract can slow down block production
Medium
CWA-2025-002Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bugThe vulnerability can be used to slow down block production. The attack requires a malicious contract, so permissioned chains are unlikely to be affected. (We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1.2: https://github.com/interchainio/security/blob/0295254e8645301ccb606d46108a45cede0a73e0/resources/CLASSIFICATION_MATRIX.md Affected versions
2.2.0
Fixed in
1.5.10
2.0.9
2.1.6
2.2.1
References
Updated Jul 09, 2025 · Source: OSV.dev |
2.0.8
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
2.1.5
unknown
1 CVE
GHSA-mx2j-7cmv-353c
GO-2025-3449
Feb 04, 2025
wasmvm: Malicious smart contract can slow down block production
Medium
CWA-2025-002Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bugThe vulnerability can be used to slow down block production. The attack requires a malicious contract, so permissioned chains are unlikely to be affected. (We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1.2: https://github.com/interchainio/security/blob/0295254e8645301ccb606d46108a45cede0a73e0/resources/CLASSIFICATION_MATRIX.md Affected versions
2.2.0
Fixed in
1.5.10
2.0.9
2.1.6
2.2.1
References
Updated Jul 09, 2025 · Source: OSV.dev |
2.1.5
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
2.2.0-rc.3
unknown
|
2.2.0-rc.3
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
2.2.0-rc.2
unknown
|
2.2.0-rc.2
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
2.2.0-rc.1
unknown
|
2.2.0-rc.1
unknown
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
2.1.4
unknown
1 CVE
GHSA-mx2j-7cmv-353c
GO-2025-3449
Feb 04, 2025
wasmvm: Malicious smart contract can slow down block production
Medium
CWA-2025-002Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bugThe vulnerability can be used to slow down block production. The attack requires a malicious contract, so permissioned chains are unlikely to be affected. (We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1.2: https://github.com/interchainio/security/blob/0295254e8645301ccb606d46108a45cede0a73e0/resources/CLASSIFICATION_MATRIX.md Affected versions
2.2.0
Fixed in
1.5.10
2.0.9
2.1.6
2.2.1
References
Updated Jul 09, 2025 · Source: OSV.dev |
2.1.4
unknown
Dependencies (32)
+ 24 more
Changelog
Compare changes
|
|
2.0.7
unknown
1 CVE
GHSA-mx2j-7cmv-353c
GO-2025-3449
Feb 04, 2025
wasmvm: Malicious smart contract can slow down block production
Medium
CWA-2025-002Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bugThe vulnerability can be used to slow down block production. The attack requires a malicious contract, so permissioned chains are unlikely to be affected. (We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1.2: https://github.com/interchainio/security/blob/0295254e8645301ccb606d46108a45cede0a73e0/resources/CLASSIFICATION_MATRIX.md Affected versions
2.2.0
Fixed in
1.5.10
2.0.9
2.1.6
2.2.1
References
Updated Jul 09, 2025 · Source: OSV.dev |
2.0.7
unknown
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
1.5.8
unknown
1 CVE
GHSA-mx2j-7cmv-353c
GO-2025-3449
Feb 04, 2025
wasmvm: Malicious smart contract can slow down block production
Medium
CWA-2025-002Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bugThe vulnerability can be used to slow down block production. The attack requires a malicious contract, so permissioned chains are unlikely to be affected. (We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1.2: https://github.com/interchainio/security/blob/0295254e8645301ccb606d46108a45cede0a73e0/resources/CLASSIFICATION_MATRIX.md Affected versions
2.2.0
Fixed in
1.5.10
2.0.9
2.1.6
2.2.1
References
Updated Jul 09, 2025 · Source: OSV.dev |
1.5.8
unknown
Dependencies (27)
+ 19 more
Changelog
Compare changes
|