evm
Activity
- Latest release
- 5mo ago
- Total releases
- 70
- Cadence
- ~12 days
- Last 12 months
- 3
Details
- License
- Apache-2.0
- First release
- Sep 09, 2017
| Version | Released | |
|---|---|---|
1.1.1
unknown
|
1.1.1
unknown
Dependencies (3)
|
|
1.1.0
unknown
|
1.1.0
unknown
Dependencies (3)
|
|
1.0.1
unknown
|
1.0.1
unknown
Dependencies (4)
|
|
1.0.0
unknown
|
1.0.0
unknown
Dependencies (4)
|
|
1.0.0-beta.2
unknown
|
1.0.0-beta.2
unknown
Dependencies (4)
|
|
1.0.0-beta.1
unknown
|
1.0.0-beta.1
unknown
Dependencies (4)
|
|
0.43.4
unknown
|
0.43.4
unknown
Dependencies (15)
+ 7 more |
|
0.43.3
unknown
|
0.43.3
unknown
Dependencies (15)
+ 7 more |
|
0.43.2
unknown
|
0.43.2
unknown
Dependencies (15)
+ 7 more |
|
0.43.1
unknown
|
0.43.1
unknown
Dependencies (15)
+ 7 more |
|
0.43.0
unknown
|
0.43.0
unknown
Dependencies (15)
+ 7 more |
|
0.42.0
unknown
|
0.42.0
unknown
Dependencies (15)
+ 7 more |
|
0.41.1
unknown
|
0.41.1
unknown
Dependencies (15)
+ 7 more |
|
1.0.0-alpha.2
unknown
|
1.0.0-alpha.2
unknown
Dependencies (3)
|
|
1.0.0-alpha.1
unknown
|
1.0.0-alpha.1
unknown
Dependencies (13)
+ 5 more |
|
0.41.0
unknown
1 CVE
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.41.0
unknown
Dependencies (15)
+ 7 more |
|
0.40.0
unknown
1 CVE
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.40.0
unknown
Dependencies (15)
+ 7 more |
|
0.39.1
unknown
1 CVE
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.39.1
unknown
Dependencies (15)
+ 7 more |
|
0.39.0
unknown
1 CVE
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.39.0
unknown
Dependencies (15)
+ 7 more |
|
0.38.0
unknown
1 CVE
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.38.0
unknown
Dependencies (15)
+ 7 more |
|
0.37.0
unknown
1 CVE
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.37.0
unknown
Dependencies (15)
+ 7 more |
|
0.36.0
unknown
1 CVE
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.36.0
unknown
Dependencies (15)
+ 7 more |
|
0.35.0
unknown
2 CVEs
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.35.0
unknown
Dependencies (15)
+ 7 more |
|
0.34.0
unknown
2 CVEs
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.34.0
unknown
Dependencies (15)
+ 7 more |
|
0.33.1
unknown
2 CVEs
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.33.1
unknown
Dependencies (15)
+ 7 more |
|
0.33.0
unknown
2 CVEs
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.33.0
unknown
Dependencies (14)
+ 6 more |
|
0.32.0
unknown
2 CVEs
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.32.0
unknown
Dependencies (14)
+ 6 more |
|
0.31.1
unknown
2 CVEs
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.31.1
unknown
Dependencies (14)
+ 6 more |
|
0.31.0
unknown
2 CVEs
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.31.0
unknown
Dependencies (14)
+ 6 more |
|
0.30.1
unknown
3 CVEs
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.30.1
unknown
Dependencies (13)
+ 5 more |
|
0.30.0
unknown
3 CVEs
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.30.0
unknown
Dependencies (13)
+ 5 more |
|
0.29.0
unknown
3 CVEs
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.29.0
unknown
Dependencies (13)
+ 5 more |
|
0.28.0
unknown
3 CVEs
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.28.0
unknown
Dependencies (13)
+ 5 more |
|
0.27.0
unknown
3 CVEs
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.27.0
unknown
Dependencies (13)
+ 5 more |
|
0.26.0
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.26.0
unknown
Dependencies (12)
+ 4 more |
|
0.25.0
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.25.0
unknown
Dependencies (12)
+ 4 more |
|
0.24.0
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.24.0
unknown
Dependencies (12)
+ 4 more |
|
0.23.0
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.23.0
unknown
Dependencies (12)
+ 4 more |
|
0.22.1
unknown
3 CVEs
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.22.1
unknown
Dependencies (10)
+ 2 more |
|
0.22.0
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.22.0
unknown
Dependencies (10)
+ 2 more |
|
0.21.0
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.21.0
unknown
Dependencies (10)
+ 2 more |
|
0.20.0
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.20.0
unknown
Dependencies (10)
+ 2 more |
|
0.19.0
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.19.0
unknown
Dependencies (10)
+ 2 more |
|
0.18.5
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.18.5
unknown
Dependencies (10)
+ 2 more |
|
0.18.4
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.18.4
unknown
Dependencies (10)
+ 2 more |
|
0.18.3
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.18.3
unknown
Dependencies (10)
+ 2 more |
|
0.18.0
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.18.0
unknown
Dependencies (10)
+ 2 more |
|
0.17.3
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.17.3
unknown
Dependencies (10)
+ 2 more |
|
0.17.2
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.17.2
unknown
Dependencies (9)
+ 1 more |
|
0.17.1
unknown
4 CVEs
CVE-2021-29511
GHSA-4jwq-572w-4388
Jan 30, 2024
Memory over-allocation in evm crate
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactPrior to the patch, when executing specific EVM opcodes related to memory operations that use PatchesThe flaw was corrected in commit WorkaroundsNone. Please upgrade your ReferencesFix commit: https://github.com/rust-blockchain/evm/commit/19ade858c430ab13eb562764a870ac9f8506f8dd For more informationIf you have any questions or comments about this advisory: Affected versions
0.22.0
0.23.0
0.24.0
0.25.0
0.26.0
Fixed in
0.21.1
0.22.1
0.23.1
0.24.1
0.25.1
0.26.1
References Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-21629
GHSA-27wg-99g8-2v4v
Jan 03, 2024
Rust EVM erroneousle handles `record_external_operation` error return
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactIn In particular, during finalization of a This issue only impacts library users with custom PatchesThe issue is patched in release 0.41.1. The commit can be seem here. WorkaroundsNone. ReferencesPatch PR #264. Fixed in
0.41.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39354
GHSA-hhc4-47rh-cr34
RUSTSEC-2022-0083
Oct 25, 2022
Incorrect is_static parameter for custom stateful precompiles in SputnikVM (evm)
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
ImpactA custom stateful precompile can use the The issue only impacts custom precompiles that actually uses PatchesPR: https://github.com/rust-blockchain/evm/pull/133 Released in v0.36.0. Older patch versions can be released on request if anyone needs them. Simply contact @sorpaas by email to request it. For more informationIf you have any questions or comments about this advisory:
Fixed in
0.36.0
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41153
GHSA-pvh2-pj76-4m96
Oct 19, 2021
Specification non-compliance in JUMPI
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
ImpactIn PatchesThis is a high severity security advisory if you use This is a low severity security advisory if you use WorkaroundsIf you are dependent on an older version of ReferencesFix PR: https://github.com/rust-blockchain/evm/pull/67 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @rakita for reporting this issue. Fixed in
0.31.0
References Updated May 04, 2026 · Source: OSV.dev |
0.17.1
unknown
Dependencies (8)
|