pallet-ethereum
Activity
- Latest release
- 5y ago
- Total releases
- 4
- Cadence
- ~2 months
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Mar 05, 2020
| Version | Released | |
|---|---|---|
3.0.0
unknown
3 CVEs
CVE-2022-39242
GHSA-v57h-6hmh-g2p4
Sep 23, 2022
Weight not properly refunded after EVM execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactPreviously, the worst case weight was always accounted as the block weight for all cases. In case of large EVM gas refunds, this can lead to block spamming attacks -- the adversary can construct blocks with transactions that have large amount of refunds or unused gases with reverts, and as a result inflate up the chain gas prices. This issue is fixed by properly refund unused weights after each EVM execution. The impact of this issue is limited in that the spamming attack would still be costly for any adversary, and it has no ability to alter any chain state. PatchesThe issue is fixed in https://github.com/paritytech/frontier/pull/851 WorkaroundsNone. ReferencesAre there any links users can visit to find out more? For more informationIf you have any questions or comments about this advisory:
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2021-41138
GHSA-vj62-g63v-f8mf
Oct 13, 2021
Validity check missing in Frontier
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactIn the newly introduced signed Frontier-specific extrinsic for The attack is limited in that the signature is always validated, and the majority of the validation is done again in the subsequent PatchesThe issue is patched in commit 146bb48849e5393004be5c88beefe76fdf009aba. ReferencesPatch PR: https://github.com/paritytech/frontier/pull/495 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @librelois, @nanocryk and the Moonbeam team for reporting and fixing this security vulnerability. References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39193
GHSA-hw4v-5x4h-c3xm
Sep 01, 2021
Transaction validity oversight in pallet-ethereum
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactA bug in PatchesPatches are applied in PR #465. WorkaroundsNone. ReferencesPatch PR: https://github.com/paritytech/frontier/pull/465 For more informationIf you have any questions or comments about this advisory:
References
Updated Jul 08, 2026 · Source: OSV.dev |
3.0.0
unknown
Dependencies (22)
+ 14 more |
|
2.0.0
unknown
3 CVEs
CVE-2022-39242
GHSA-v57h-6hmh-g2p4
Sep 23, 2022
Weight not properly refunded after EVM execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactPreviously, the worst case weight was always accounted as the block weight for all cases. In case of large EVM gas refunds, this can lead to block spamming attacks -- the adversary can construct blocks with transactions that have large amount of refunds or unused gases with reverts, and as a result inflate up the chain gas prices. This issue is fixed by properly refund unused weights after each EVM execution. The impact of this issue is limited in that the spamming attack would still be costly for any adversary, and it has no ability to alter any chain state. PatchesThe issue is fixed in https://github.com/paritytech/frontier/pull/851 WorkaroundsNone. ReferencesAre there any links users can visit to find out more? For more informationIf you have any questions or comments about this advisory:
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2021-41138
GHSA-vj62-g63v-f8mf
Oct 13, 2021
Validity check missing in Frontier
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactIn the newly introduced signed Frontier-specific extrinsic for The attack is limited in that the signature is always validated, and the majority of the validation is done again in the subsequent PatchesThe issue is patched in commit 146bb48849e5393004be5c88beefe76fdf009aba. ReferencesPatch PR: https://github.com/paritytech/frontier/pull/495 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @librelois, @nanocryk and the Moonbeam team for reporting and fixing this security vulnerability. References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39193
GHSA-hw4v-5x4h-c3xm
Sep 01, 2021
Transaction validity oversight in pallet-ethereum
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactA bug in PatchesPatches are applied in PR #465. WorkaroundsNone. ReferencesPatch PR: https://github.com/paritytech/frontier/pull/465 For more informationIf you have any questions or comments about this advisory:
References
Updated Jul 08, 2026 · Source: OSV.dev |
2.0.0
unknown
Dependencies (22)
+ 14 more |
|
1.0.0
unknown
3 CVEs
CVE-2022-39242
GHSA-v57h-6hmh-g2p4
Sep 23, 2022
Weight not properly refunded after EVM execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactPreviously, the worst case weight was always accounted as the block weight for all cases. In case of large EVM gas refunds, this can lead to block spamming attacks -- the adversary can construct blocks with transactions that have large amount of refunds or unused gases with reverts, and as a result inflate up the chain gas prices. This issue is fixed by properly refund unused weights after each EVM execution. The impact of this issue is limited in that the spamming attack would still be costly for any adversary, and it has no ability to alter any chain state. PatchesThe issue is fixed in https://github.com/paritytech/frontier/pull/851 WorkaroundsNone. ReferencesAre there any links users can visit to find out more? For more informationIf you have any questions or comments about this advisory:
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2021-41138
GHSA-vj62-g63v-f8mf
Oct 13, 2021
Validity check missing in Frontier
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactIn the newly introduced signed Frontier-specific extrinsic for The attack is limited in that the signature is always validated, and the majority of the validation is done again in the subsequent PatchesThe issue is patched in commit 146bb48849e5393004be5c88beefe76fdf009aba. ReferencesPatch PR: https://github.com/paritytech/frontier/pull/495 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @librelois, @nanocryk and the Moonbeam team for reporting and fixing this security vulnerability. References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39193
GHSA-hw4v-5x4h-c3xm
Sep 01, 2021
Transaction validity oversight in pallet-ethereum
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactA bug in PatchesPatches are applied in PR #465. WorkaroundsNone. ReferencesPatch PR: https://github.com/paritytech/frontier/pull/465 For more informationIf you have any questions or comments about this advisory:
References
Updated Jul 08, 2026 · Source: OSV.dev |
1.0.0
unknown
Dependencies (22)
+ 14 more |
|
0.1.0
unknown
3 CVEs
CVE-2022-39242
GHSA-v57h-6hmh-g2p4
Sep 23, 2022
Weight not properly refunded after EVM execution
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactPreviously, the worst case weight was always accounted as the block weight for all cases. In case of large EVM gas refunds, this can lead to block spamming attacks -- the adversary can construct blocks with transactions that have large amount of refunds or unused gases with reverts, and as a result inflate up the chain gas prices. This issue is fixed by properly refund unused weights after each EVM execution. The impact of this issue is limited in that the spamming attack would still be costly for any adversary, and it has no ability to alter any chain state. PatchesThe issue is fixed in https://github.com/paritytech/frontier/pull/851 WorkaroundsNone. ReferencesAre there any links users can visit to find out more? For more informationIf you have any questions or comments about this advisory:
References Updated Oct 24, 2024 · Source: OSV.dev
CVE-2021-41138
GHSA-vj62-g63v-f8mf
Oct 13, 2021
Validity check missing in Frontier
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactIn the newly introduced signed Frontier-specific extrinsic for The attack is limited in that the signature is always validated, and the majority of the validation is done again in the subsequent PatchesThe issue is patched in commit 146bb48849e5393004be5c88beefe76fdf009aba. ReferencesPatch PR: https://github.com/paritytech/frontier/pull/495 For more informationIf you have any questions or comments about this advisory:
Special thanksSpecial thanks to @librelois, @nanocryk and the Moonbeam team for reporting and fixing this security vulnerability. References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2021-39193
GHSA-hw4v-5x4h-c3xm
Sep 01, 2021
Transaction validity oversight in pallet-ethereum
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
ImpactA bug in PatchesPatches are applied in PR #465. WorkaroundsNone. ReferencesPatch PR: https://github.com/paritytech/frontier/pull/465 For more informationIf you have any questions or comments about this advisory:
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.1.0
unknown
|