github.com/cheqd/cheqd-node
Activity
- Latest release
- 10mo ago
- Total releases
- 20
- Cadence
- ~12 days
- Last 12 months
- 1
Reach
- Stars
- —
Details
- First release
- Mar 03, 2023
| Version | Released | |
|---|---|---|
v1.4.6-pseudo-version-4.1.6
pre
2 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev |
v1.4.6-pseudo-version-4.1.6
pre
Dependencies (49)
+ 41 more |
|
v1.4.6-pseudo-version-4.0.0
pre
2 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev |
v1.4.6-pseudo-version-4.0.0
pre
Dependencies (47)
+ 39 more |
|
v1.4.6-pseudo-version-3.1.5
pre
2 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev |
v1.4.6-pseudo-version-3.1.5
pre
Dependencies (33)
+ 25 more |
|
v1.4.6-pseudo-version-3.0.1
pre
2 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev |
v1.4.6-pseudo-version-3.0.1
pre
Dependencies (33)
+ 25 more |
|
v1.4.5
patch
2 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev |
v1.4.5
patch
Dependencies (28)
+ 20 more |
|
v1.4.5-develop.3
pre
2 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev |
v1.4.5-develop.3
pre
Dependencies (28)
+ 20 more |
|
v1.4.5-develop.2
pre
2 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev |
v1.4.5-develop.2
pre
Dependencies (28)
+ 20 more |
|
v1.4.5-develop.1
pre
2 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev |
v1.4.5-develop.1
pre
Dependencies (28)
+ 20 more |
|
v1.4.4
patch
2 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev |
v1.4.4
patch
Dependencies (28)
+ 20 more |
|
v1.4.3-develop.1
pre
3 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev
GHSA-8qxh-2gh8-r923
Jun 12, 2023
cheqd-node subject to Cosmos SDK "Barberry" vulnerability
High
ImpactThis vulnerability dubbed "Barberry" affects the Cosmos SDK framework used by It impacts the way Cosmos SDK handles vesting accounts, and can therefore be a high-impact vulnerability for any network running the framework. There is no vulnerability in the DID/resource modules for PatchesNode operators are requested to upgrade to cheqd-node v1.4.4. This is not a state-breaking release and does not require a coordinated upgrade across all node operators. This vulnerability was patched in Cosmos SDK v0.46.13. Since this version switches to Go v1.19 and also changes the namespace of many Cosmos protobuf packages, the Barberry fix was backported to cheqd's fork of Cosmos SDK. MitigationWhen at least ~33% of the voting power of the network has deployed the recommended version of the software, any attack would be unsuccessful but cause a chain halt. Once at least ~67% of the voting power of the network has deployed recommended version of the software, the attack would be unsuccessful without a chain halt. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.4
References Updated Jun 12, 2023 · Source: OSV.dev |
v1.4.3-develop.1
pre
Dependencies (28)
+ 20 more |
|
v1.4.3
patch
3 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev
GHSA-8qxh-2gh8-r923
Jun 12, 2023
cheqd-node subject to Cosmos SDK "Barberry" vulnerability
High
ImpactThis vulnerability dubbed "Barberry" affects the Cosmos SDK framework used by It impacts the way Cosmos SDK handles vesting accounts, and can therefore be a high-impact vulnerability for any network running the framework. There is no vulnerability in the DID/resource modules for PatchesNode operators are requested to upgrade to cheqd-node v1.4.4. This is not a state-breaking release and does not require a coordinated upgrade across all node operators. This vulnerability was patched in Cosmos SDK v0.46.13. Since this version switches to Go v1.19 and also changes the namespace of many Cosmos protobuf packages, the Barberry fix was backported to cheqd's fork of Cosmos SDK. MitigationWhen at least ~33% of the voting power of the network has deployed the recommended version of the software, any attack would be unsuccessful but cause a chain halt. Once at least ~67% of the voting power of the network has deployed recommended version of the software, the attack would be unsuccessful without a chain halt. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.4
References Updated Jun 12, 2023 · Source: OSV.dev |
v1.4.3
patch
Dependencies (28)
+ 20 more |
|
v1.4.2
patch
3 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev
GHSA-8qxh-2gh8-r923
Jun 12, 2023
cheqd-node subject to Cosmos SDK "Barberry" vulnerability
High
ImpactThis vulnerability dubbed "Barberry" affects the Cosmos SDK framework used by It impacts the way Cosmos SDK handles vesting accounts, and can therefore be a high-impact vulnerability for any network running the framework. There is no vulnerability in the DID/resource modules for PatchesNode operators are requested to upgrade to cheqd-node v1.4.4. This is not a state-breaking release and does not require a coordinated upgrade across all node operators. This vulnerability was patched in Cosmos SDK v0.46.13. Since this version switches to Go v1.19 and also changes the namespace of many Cosmos protobuf packages, the Barberry fix was backported to cheqd's fork of Cosmos SDK. MitigationWhen at least ~33% of the voting power of the network has deployed the recommended version of the software, any attack would be unsuccessful but cause a chain halt. Once at least ~67% of the voting power of the network has deployed recommended version of the software, the attack would be unsuccessful without a chain halt. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.4
References Updated Jun 12, 2023 · Source: OSV.dev |
v1.4.2
patch
Dependencies (28)
+ 20 more |
|
v1.4.1-develop.3
pre
4 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev
GHSA-8qxh-2gh8-r923
Jun 12, 2023
cheqd-node subject to Cosmos SDK "Barberry" vulnerability
High
ImpactThis vulnerability dubbed "Barberry" affects the Cosmos SDK framework used by It impacts the way Cosmos SDK handles vesting accounts, and can therefore be a high-impact vulnerability for any network running the framework. There is no vulnerability in the DID/resource modules for PatchesNode operators are requested to upgrade to cheqd-node v1.4.4. This is not a state-breaking release and does not require a coordinated upgrade across all node operators. This vulnerability was patched in Cosmos SDK v0.46.13. Since this version switches to Go v1.19 and also changes the namespace of many Cosmos protobuf packages, the Barberry fix was backported to cheqd's fork of Cosmos SDK. MitigationWhen at least ~33% of the voting power of the network has deployed the recommended version of the software, any attack would be unsuccessful but cause a chain halt. Once at least ~67% of the voting power of the network has deployed recommended version of the software, the attack would be unsuccessful without a chain halt. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.4
References Updated Jun 12, 2023 · Source: OSV.dev
GHSA-7c94-gvvj-r3mg
Jun 05, 2023
cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability
Low
ImpactThis vulnerability affects the
There is no vulnerability in the DID/resource modules for cheqd-node. PatchesNode operators are requested to upgrade to cheqd-node v1.4.2. This is a non-state breaking release, and does not require a coordinated upgrade across all node operators. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.2
References
Updated Jun 05, 2023 · Source: OSV.dev |
v1.4.1-develop.3
pre
Dependencies (28)
+ 20 more |
|
v1.4.1
patch
4 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev
GHSA-8qxh-2gh8-r923
Jun 12, 2023
cheqd-node subject to Cosmos SDK "Barberry" vulnerability
High
ImpactThis vulnerability dubbed "Barberry" affects the Cosmos SDK framework used by It impacts the way Cosmos SDK handles vesting accounts, and can therefore be a high-impact vulnerability for any network running the framework. There is no vulnerability in the DID/resource modules for PatchesNode operators are requested to upgrade to cheqd-node v1.4.4. This is not a state-breaking release and does not require a coordinated upgrade across all node operators. This vulnerability was patched in Cosmos SDK v0.46.13. Since this version switches to Go v1.19 and also changes the namespace of many Cosmos protobuf packages, the Barberry fix was backported to cheqd's fork of Cosmos SDK. MitigationWhen at least ~33% of the voting power of the network has deployed the recommended version of the software, any attack would be unsuccessful but cause a chain halt. Once at least ~67% of the voting power of the network has deployed recommended version of the software, the attack would be unsuccessful without a chain halt. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.4
References Updated Jun 12, 2023 · Source: OSV.dev
GHSA-7c94-gvvj-r3mg
Jun 05, 2023
cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability
Low
ImpactThis vulnerability affects the
There is no vulnerability in the DID/resource modules for cheqd-node. PatchesNode operators are requested to upgrade to cheqd-node v1.4.2. This is a non-state breaking release, and does not require a coordinated upgrade across all node operators. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.2
References
Updated Jun 05, 2023 · Source: OSV.dev |
v1.4.1
patch
Dependencies (28)
+ 20 more |
|
v1.4.1-develop.2
pre
4 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev
GHSA-8qxh-2gh8-r923
Jun 12, 2023
cheqd-node subject to Cosmos SDK "Barberry" vulnerability
High
ImpactThis vulnerability dubbed "Barberry" affects the Cosmos SDK framework used by It impacts the way Cosmos SDK handles vesting accounts, and can therefore be a high-impact vulnerability for any network running the framework. There is no vulnerability in the DID/resource modules for PatchesNode operators are requested to upgrade to cheqd-node v1.4.4. This is not a state-breaking release and does not require a coordinated upgrade across all node operators. This vulnerability was patched in Cosmos SDK v0.46.13. Since this version switches to Go v1.19 and also changes the namespace of many Cosmos protobuf packages, the Barberry fix was backported to cheqd's fork of Cosmos SDK. MitigationWhen at least ~33% of the voting power of the network has deployed the recommended version of the software, any attack would be unsuccessful but cause a chain halt. Once at least ~67% of the voting power of the network has deployed recommended version of the software, the attack would be unsuccessful without a chain halt. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.4
References Updated Jun 12, 2023 · Source: OSV.dev
GHSA-7c94-gvvj-r3mg
Jun 05, 2023
cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability
Low
ImpactThis vulnerability affects the
There is no vulnerability in the DID/resource modules for cheqd-node. PatchesNode operators are requested to upgrade to cheqd-node v1.4.2. This is a non-state breaking release, and does not require a coordinated upgrade across all node operators. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.2
References
Updated Jun 05, 2023 · Source: OSV.dev |
v1.4.1-develop.2
pre
Dependencies (28)
+ 20 more |
|
v1.4.1-develop.1
pre
4 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev
GHSA-8qxh-2gh8-r923
Jun 12, 2023
cheqd-node subject to Cosmos SDK "Barberry" vulnerability
High
ImpactThis vulnerability dubbed "Barberry" affects the Cosmos SDK framework used by It impacts the way Cosmos SDK handles vesting accounts, and can therefore be a high-impact vulnerability for any network running the framework. There is no vulnerability in the DID/resource modules for PatchesNode operators are requested to upgrade to cheqd-node v1.4.4. This is not a state-breaking release and does not require a coordinated upgrade across all node operators. This vulnerability was patched in Cosmos SDK v0.46.13. Since this version switches to Go v1.19 and also changes the namespace of many Cosmos protobuf packages, the Barberry fix was backported to cheqd's fork of Cosmos SDK. MitigationWhen at least ~33% of the voting power of the network has deployed the recommended version of the software, any attack would be unsuccessful but cause a chain halt. Once at least ~67% of the voting power of the network has deployed recommended version of the software, the attack would be unsuccessful without a chain halt. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.4
References Updated Jun 12, 2023 · Source: OSV.dev
GHSA-7c94-gvvj-r3mg
Jun 05, 2023
cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability
Low
ImpactThis vulnerability affects the
There is no vulnerability in the DID/resource modules for cheqd-node. PatchesNode operators are requested to upgrade to cheqd-node v1.4.2. This is a non-state breaking release, and does not require a coordinated upgrade across all node operators. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.2
References
Updated Jun 05, 2023 · Source: OSV.dev |
v1.4.1-develop.1
pre
Dependencies (28)
+ 20 more |
|
v1.4.0
initial
4 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev
GHSA-8qxh-2gh8-r923
Jun 12, 2023
cheqd-node subject to Cosmos SDK "Barberry" vulnerability
High
ImpactThis vulnerability dubbed "Barberry" affects the Cosmos SDK framework used by It impacts the way Cosmos SDK handles vesting accounts, and can therefore be a high-impact vulnerability for any network running the framework. There is no vulnerability in the DID/resource modules for PatchesNode operators are requested to upgrade to cheqd-node v1.4.4. This is not a state-breaking release and does not require a coordinated upgrade across all node operators. This vulnerability was patched in Cosmos SDK v0.46.13. Since this version switches to Go v1.19 and also changes the namespace of many Cosmos protobuf packages, the Barberry fix was backported to cheqd's fork of Cosmos SDK. MitigationWhen at least ~33% of the voting power of the network has deployed the recommended version of the software, any attack would be unsuccessful but cause a chain halt. Once at least ~67% of the voting power of the network has deployed recommended version of the software, the attack would be unsuccessful without a chain halt. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.4
References Updated Jun 12, 2023 · Source: OSV.dev
GHSA-7c94-gvvj-r3mg
Jun 05, 2023
cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability
Low
ImpactThis vulnerability affects the
There is no vulnerability in the DID/resource modules for cheqd-node. PatchesNode operators are requested to upgrade to cheqd-node v1.4.2. This is a non-state breaking release, and does not require a coordinated upgrade across all node operators. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.2
References
Updated Jun 05, 2023 · Source: OSV.dev |
v1.4.0
initial
Dependencies (28)
+ 20 more |
|
v1.4.0-develop.2
pre
4 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev
GHSA-8qxh-2gh8-r923
Jun 12, 2023
cheqd-node subject to Cosmos SDK "Barberry" vulnerability
High
ImpactThis vulnerability dubbed "Barberry" affects the Cosmos SDK framework used by It impacts the way Cosmos SDK handles vesting accounts, and can therefore be a high-impact vulnerability for any network running the framework. There is no vulnerability in the DID/resource modules for PatchesNode operators are requested to upgrade to cheqd-node v1.4.4. This is not a state-breaking release and does not require a coordinated upgrade across all node operators. This vulnerability was patched in Cosmos SDK v0.46.13. Since this version switches to Go v1.19 and also changes the namespace of many Cosmos protobuf packages, the Barberry fix was backported to cheqd's fork of Cosmos SDK. MitigationWhen at least ~33% of the voting power of the network has deployed the recommended version of the software, any attack would be unsuccessful but cause a chain halt. Once at least ~67% of the voting power of the network has deployed recommended version of the software, the attack would be unsuccessful without a chain halt. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.4
References Updated Jun 12, 2023 · Source: OSV.dev
GHSA-7c94-gvvj-r3mg
Jun 05, 2023
cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability
Low
ImpactThis vulnerability affects the
There is no vulnerability in the DID/resource modules for cheqd-node. PatchesNode operators are requested to upgrade to cheqd-node v1.4.2. This is a non-state breaking release, and does not require a coordinated upgrade across all node operators. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.2
References
Updated Jun 05, 2023 · Source: OSV.dev |
v1.4.0-develop.2
pre
Dependencies (28)
+ 20 more |
|
v1.4.0-develop.1
pre
4 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev
GHSA-8qxh-2gh8-r923
Jun 12, 2023
cheqd-node subject to Cosmos SDK "Barberry" vulnerability
High
ImpactThis vulnerability dubbed "Barberry" affects the Cosmos SDK framework used by It impacts the way Cosmos SDK handles vesting accounts, and can therefore be a high-impact vulnerability for any network running the framework. There is no vulnerability in the DID/resource modules for PatchesNode operators are requested to upgrade to cheqd-node v1.4.4. This is not a state-breaking release and does not require a coordinated upgrade across all node operators. This vulnerability was patched in Cosmos SDK v0.46.13. Since this version switches to Go v1.19 and also changes the namespace of many Cosmos protobuf packages, the Barberry fix was backported to cheqd's fork of Cosmos SDK. MitigationWhen at least ~33% of the voting power of the network has deployed the recommended version of the software, any attack would be unsuccessful but cause a chain halt. Once at least ~67% of the voting power of the network has deployed recommended version of the software, the attack would be unsuccessful without a chain halt. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.4
References Updated Jun 12, 2023 · Source: OSV.dev
GHSA-7c94-gvvj-r3mg
Jun 05, 2023
cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability
Low
ImpactThis vulnerability affects the
There is no vulnerability in the DID/resource modules for cheqd-node. PatchesNode operators are requested to upgrade to cheqd-node v1.4.2. This is a non-state breaking release, and does not require a coordinated upgrade across all node operators. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.2
References
Updated Jun 05, 2023 · Source: OSV.dev |
v1.4.0-develop.1
pre
Dependencies (28)
+ 20 more |
|
v1.3.1-develop.1
pre
4 CVEs
GO-2025-3520
GHSA-h2rp-8vpx-q9r4
Mar 25, 2025
cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002) in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.8. References
Updated Mar 25, 2025 · Source: OSV.dev
GO-2025-3514
GHSA-33cr-m232-xqch
Mar 13, 2025
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cheqd/cheqd-node. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/cheqd/cheqd-node before v3.1.7. References Updated Mar 13, 2025 · Source: OSV.dev
GHSA-8qxh-2gh8-r923
Jun 12, 2023
cheqd-node subject to Cosmos SDK "Barberry" vulnerability
High
ImpactThis vulnerability dubbed "Barberry" affects the Cosmos SDK framework used by It impacts the way Cosmos SDK handles vesting accounts, and can therefore be a high-impact vulnerability for any network running the framework. There is no vulnerability in the DID/resource modules for PatchesNode operators are requested to upgrade to cheqd-node v1.4.4. This is not a state-breaking release and does not require a coordinated upgrade across all node operators. This vulnerability was patched in Cosmos SDK v0.46.13. Since this version switches to Go v1.19 and also changes the namespace of many Cosmos protobuf packages, the Barberry fix was backported to cheqd's fork of Cosmos SDK. MitigationWhen at least ~33% of the voting power of the network has deployed the recommended version of the software, any attack would be unsuccessful but cause a chain halt. Once at least ~67% of the voting power of the network has deployed recommended version of the software, the attack would be unsuccessful without a chain halt. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.4
References Updated Jun 12, 2023 · Source: OSV.dev
GHSA-7c94-gvvj-r3mg
Jun 05, 2023
cheqd-node affected by Inter-blockchain Communication (IBC) protocol "Huckleberry" vulnerability
Low
ImpactThis vulnerability affects the
There is no vulnerability in the DID/resource modules for cheqd-node. PatchesNode operators are requested to upgrade to cheqd-node v1.4.2. This is a non-state breaking release, and does not require a coordinated upgrade across all node operators. WorkaroundsNo. Node operators are recommended to upgrade to the latest release version. ReferencesFixed in
1.4.2
References
Updated Jun 05, 2023 · Source: OSV.dev |
v1.3.1-develop.1
pre
Dependencies (28)
+ 20 more |