tendermint-light-client-verifier
Activity
- Latest release
- 1y ago
- Total releases
- 38
- Cadence
- ~23 days
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Jan 14, 2022
| Version | Released | |
|---|---|---|
0.40.4
unknown
|
0.40.4
unknown
Dependencies (7)
|
|
0.40.3
unknown
|
0.40.3
unknown
Dependencies (7)
|
|
0.40.2
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.40.2
unknown
Dependencies (6)
|
|
0.40.1
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.40.1
unknown
Dependencies (6)
|
|
0.40.0
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.40.0
unknown
Dependencies (6)
|
|
0.39.1
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.39.1
unknown
Dependencies (6)
|
|
0.39.0
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.39.0
unknown
Dependencies (6)
|
|
0.38.1
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.38.1
unknown
Dependencies (6)
|
|
0.38.0
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.38.0
unknown
Dependencies (6)
|
|
0.37.0
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.37.0
unknown
Dependencies (6)
|
|
0.36.0
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.36.0
unknown
Dependencies (6)
|
|
0.35.0
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.35.0
unknown
Dependencies (6)
|
|
0.34.1
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.34.1
unknown
Dependencies (6)
|
|
0.34.0
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.34.0
unknown
Dependencies (6)
|
|
0.33.2
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.33.2
unknown
Dependencies (6)
|
|
0.33.1
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.33.1
unknown
Dependencies (6)
|
|
0.33.0
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.33.0
unknown
Dependencies (6)
|
|
0.32.2
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.32.2
unknown
Dependencies (6)
|
|
0.32.1
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.32.1
unknown
Dependencies (6)
|
|
0.32.0
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.32.0
unknown
Dependencies (6)
|
|
0.31.1
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.31.1
unknown
Dependencies (6)
|
|
0.31.0
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.31.0
unknown
Dependencies (6)
|
|
0.30.0
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.30.0
unknown
Dependencies (6)
|
|
0.29.1
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.29.1
unknown
Dependencies (6)
|
|
0.29.0
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.29.0
unknown
Dependencies (6)
|
|
0.28.0
unknown
1 CVE
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev |
0.28.0
unknown
Dependencies (5)
|
|
0.28.0-pre.1
unknown
2 CVEs
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.28.0-pre.1
unknown
Dependencies (5)
|
|
0.27.0
unknown
2 CVEs
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.27.0
unknown
Dependencies (5)
|
|
0.26.0
unknown
2 CVEs
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.26.0
unknown
Dependencies (5)
|
|
0.25.0
unknown
2 CVEs
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.25.0
unknown
Dependencies (5)
|
|
0.23.9
unknown
2 CVEs
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.9
unknown
Dependencies (5)
|
|
0.23.8
unknown
2 CVEs
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.8
unknown
Dependencies (5)
|
|
0.23.8-pre.1
unknown
2 CVEs
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.8-pre.1
unknown
Dependencies (5)
|
|
0.24.0-pre.2
unknown
2 CVEs
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.24.0-pre.2
unknown
Dependencies (5)
|
|
0.23.7
unknown
2 CVEs
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.7
unknown
Dependencies (5)
|
|
0.23.6
unknown
2 CVEs
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.6
unknown
Dependencies (5)
|
|
0.24.0-pre.1
unknown
2 CVEs
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.24.0-pre.1
unknown
Dependencies (6)
|
|
0.23.5
unknown
2 CVEs
GHSA-6jrf-4jv4-r9mw
Apr 09, 2025
tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators
High
Network
High
None
None
Name: ISA-2025-003: Malicious validator can spoof votes from other validators Component: tendermint-rs Criticality: High (Catastrophic Impact; Rare Likelihood per ACMv1.2) Affected versions: <= v0.40.2 Affected users: Everyone Descriptiontendermint-rs contains a critical vulnerability in its light client implementation due to insecure handling of corrupted validator sets. Because it doesn't check that the validator address is correctly derived from the validator's public key when counting votes, it is possible to spoof votes from other validators. The result is being able to construct the malicious block and cheat the light client. The light client will accept such a block, seemingly signed by 2/3+ majority. PatchesThe new tendermint-rs release v0.40.3 fixes this issue. Unreleased code in the main branch is patched as well. WorkaroundsThere are no known workarounds for this issue. Timeline
This issue was reported by Felix Wilhelm from Asymmetric Research. Fixed in
0.40.3
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-23507
GHSA-xqqc-c5gw-c5r5
Dec 14, 2022
Tendermint light client verification not taking into account chain ID
5.4
/ 10
Medium
Network
High
None
None
Changed
Low
Low
None
ImpactAnyone using the At present, the light client does not check that the chain IDs of the trusted and untrusted headers match, resulting in a possible attack vector where someone who finds a header from an untrusted chain that satisfies all other verification conditions (e.g. enough overlapping validator signatures) could fool a light client. The attack vector is currently theoretical, and no proof-of-concept exists yet to exploit it on live networks. PatchesUsers of the light client-related crates can currently upgrade to WorkaroundsNone ReferencesFixed in
0.28.0
References Updated Nov 08, 2023 · Source: OSV.dev |
0.23.5
unknown
Dependencies (6)
|