fuel-vm
Activity
- Latest release
- 4mo ago
- Total releases
- 115
- Cadence
- ~11 days
- Last 12 months
- 7
Details
- License
- BUSL-1.1
- First release
- Dec 24, 2021
| Version | Released | |
|---|---|---|
0.66.4
unknown
|
0.66.4
unknown
Dependencies (44)
+ 36 more |
|
0.66.3
unknown
|
0.66.3
unknown
Dependencies (44)
+ 36 more |
|
0.66.2
unknown
|
0.66.2
unknown
Dependencies (44)
+ 36 more |
|
0.66.1
unknown
|
0.66.1
unknown
Dependencies (44)
+ 36 more |
|
0.66.0
unknown
|
0.66.0
unknown
Dependencies (44)
+ 36 more |
|
0.65.0
unknown
|
0.65.0
unknown
Dependencies (44)
+ 36 more |
|
0.64.0
unknown
|
0.64.0
unknown
Dependencies (44)
+ 36 more |
|
0.63.0
unknown
|
0.63.0
unknown
Dependencies (44)
+ 36 more |
|
0.62.0
unknown
|
0.62.0
unknown
Dependencies (44)
+ 36 more |
|
0.61.1
unknown
|
0.61.1
unknown
Dependencies (44)
+ 36 more |
|
0.61.0
unknown
|
0.61.0
unknown
Dependencies (44)
+ 36 more |
|
0.60.2
unknown
|
0.60.2
unknown
Dependencies (44)
+ 36 more |
|
0.60.1
unknown
|
0.60.1
unknown
Dependencies (44)
+ 36 more |
|
0.59.3
unknown
|
0.59.3
unknown
Dependencies (46)
+ 38 more |
|
0.60.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.60.0
unknown
Dependencies (44)
+ 36 more |
|
0.59.2
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.59.2
unknown
Dependencies (46)
+ 38 more |
|
0.59.1
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.59.1
unknown
Dependencies (46)
+ 38 more |
|
0.59.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.59.0
unknown
Dependencies (46)
+ 38 more |
|
0.58.2
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.58.2
unknown
Dependencies (44)
+ 36 more |
|
0.58.1
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.58.1
unknown
Dependencies (44)
+ 36 more |
|
0.58.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.58.0
unknown
Dependencies (44)
+ 36 more |
|
0.57.1
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.57.1
unknown
Dependencies (44)
+ 36 more |
|
0.57.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.57.0
unknown
Dependencies (44)
+ 36 more |
|
0.56.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.56.0
unknown
Dependencies (43)
+ 35 more |
|
0.55.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.55.0
unknown
Dependencies (43)
+ 35 more |
|
0.54.1
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.54.1
unknown
Dependencies (43)
+ 35 more |
|
0.54.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.54.0
unknown
Dependencies (43)
+ 35 more |
|
0.53.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.53.0
unknown
Dependencies (42)
+ 34 more |
|
0.52.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.52.0
unknown
Dependencies (42)
+ 34 more |
|
0.51.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.51.0
unknown
Dependencies (42)
+ 34 more |
|
0.50.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.50.0
unknown
Dependencies (41)
+ 33 more |
|
0.49.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.49.0
unknown
Dependencies (41)
+ 33 more |
|
0.48.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.48.0
unknown
Dependencies (41)
+ 33 more |
|
0.47.1
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.47.1
unknown
Dependencies (40)
+ 32 more |
|
0.47.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.47.0
unknown
Dependencies (40)
+ 32 more |
|
0.46.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.46.0
unknown
Dependencies (40)
+ 32 more |
|
0.45.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.45.0
unknown
Dependencies (40)
+ 32 more |
|
0.44.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.44.0
unknown
Dependencies (40)
+ 32 more |
|
0.43.2
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.43.2
unknown
Dependencies (40)
+ 32 more |
|
0.43.1
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.43.1
unknown
Dependencies (40)
+ 32 more |
|
0.43.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.43.0
unknown
Dependencies (40)
+ 32 more |
|
0.42.3
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.42.3
unknown
Dependencies (40)
+ 32 more |
|
0.42.2
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.42.2
unknown
Dependencies (40)
+ 32 more |
|
0.42.1
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.42.1
unknown
Dependencies (40)
+ 32 more |
|
0.42.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.42.0
unknown
Dependencies (40)
+ 32 more |
|
0.41.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.41.0
unknown
Dependencies (40)
+ 32 more |
|
0.40.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.40.0
unknown
Dependencies (40)
+ 32 more |
|
0.39.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.39.0
unknown
Dependencies (40)
+ 32 more |
|
0.38.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.38.0
unknown
Dependencies (40)
+ 32 more |
|
0.37.0
unknown
1 CVE
GHSA-2pgj-5cv2-6xxw
Oct 08, 2025
FuelVM is vulnerable to heap memory allocation re-use bug
High
Network
Low
None
None
ImpactA memory safety vulnerability was present in the Fuel Virtual Machine (FuelVM), where memory reads could bypass expected access controls. Specifically, when a smart contract performed a All users running affected versions of FuelVM that relied on strict memory isolation between smart contracts were impacted. PatchesThe vulnerability was patched by modifying the FuelVM to ensure that memory deallocated with WorkaroundsThere were no reliable workarounds that fully mitigated the vulnerability. While developers could manually zero out sensitive memory regions before returning from a function, this approach was error-prone and could not be enforced at the VM level. Upgrading to a patched version remained the recommended course of action. References
Fixed in
0.59.3
0.60.1
References Updated Oct 08, 2025 · Source: OSV.dev |
0.37.0
unknown
Dependencies (37)
+ 29 more |