github.com/cosmos/cosmos-sdk
Framework for building performant, customizable blockchains with native interoperability
Activity
- Latest release
- Mar 25, 2026
- Total releases
- 50
- Cadence
- ~2 months
- Last 12 months
- 1
Reach
- Stars
- 7.0k
Details
- First release
- Apr 09, 2018
| Version | Released | |
|---|---|---|
v0.54.0-rc.3
pre
3 CVEs
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.54.0-rc.3
pre
Dependencies (77)
+ 69 more |
|
v0.53.1
minor
4 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.53.1
minor
Dependencies (62)
+ 54 more |
|
v0.53.0-beta.3
pre
4 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.53.0-beta.3
pre
Dependencies (59)
+ 51 more |
|
v0.52.0-rc.1
pre
4 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.52.0-rc.1
pre
Dependencies (59)
+ 51 more |
|
v0.47.14
patch
6 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.47.14
patch
Dependencies (62)
+ 54 more |
|
v0.50.9
patch
7 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.50.9
patch
Dependencies (59)
+ 51 more |
|
v0.50.9-lsm
pre
7 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.50.9-lsm
pre
Dependencies (60)
+ 52 more |
|
v0.47.12
patch
6 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.47.12
patch
Dependencies (62)
+ 54 more |
|
v0.47.11
patch
6 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.47.11
patch
Dependencies (62)
+ 54 more |
|
v0.47.10-ics-lsm
pre
7 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.47.10-ics-lsm
pre
Dependencies (65)
+ 57 more |
|
v0.47.9-ics-lsm
pre
9 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.47.9-ics-lsm
pre
Dependencies (65)
+ 57 more |
|
v0.50.2
minor
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2638
GHSA-95rx-m9m5-m94v
May 10, 2024
ValidateVoteExtensions function in Cosmos SDK may allow incorrect voting power assumptions in github.com/cosmos/cosmos-sdk The default ValidateVoteExtensions helper function infers total voting power based on the injected VoteExtension, which are injected by the proposer. If your chain utilizes the ValidateVoteExtensions helper in ProcessProposal, a dishonest proposer can potentially mutate voting power of each validator it includes in the injected VoteExtension, which could have potentially unexpected or negative consequences on modified state. Additional validation on injected VoteExtension data was added to confirm voting power against the state machine. Fixed in
0.50.5
References Updated May 20, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.50.2
minor
Dependencies (59)
+ 51 more |
|
v0.47.6
patch
9 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.47.6
patch
Dependencies (61)
+ 53 more |
|
v0.46.16
patch
9 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.46.16
patch
Dependencies (55)
+ 47 more |
|
v0.47.5
patch
9 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.47.5
patch
Dependencies (60)
+ 52 more |
|
v0.47.4
minor
9 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.47.4
minor
Dependencies (60)
+ 52 more |
|
v0.46.13-rc.0
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-j2cr-jc39-wpx5
GHSA-w44m-8mv2-v78h
GO-2023-1861
Jul 07, 2023
Barberry Security Advisory - regarding x/auth periodic vesting accounts
Medium
ImpactIn Patches>= v0.46.13 for Cosmos SDK v0.46.x >= v0.47.3 for Cosmos SDK v0.47.x If a network backported periodic vesting accounts to earlier versions of the SDK, those networks are affected too. WorkaroundsThere is no workaround for this issue. Upgrade immediately. References
Fixed in
0.46.13
0.47.3
References
Updated Nov 08, 2023 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.46.13-rc.0
pre
Dependencies (55)
+ 47 more |
|
v0.45.14-ics
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.45.14-ics
pre
Dependencies (47)
+ 39 more |
|
v0.45.11-ics
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.45.11-ics
pre
Dependencies (47)
+ 39 more |
|
v0.45.8
patch
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.45.8
patch
Dependencies (47)
+ 39 more |
|
v0.46.1
patch
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-j2cr-jc39-wpx5
GHSA-w44m-8mv2-v78h
GO-2023-1861
Jul 07, 2023
Barberry Security Advisory - regarding x/auth periodic vesting accounts
Medium
ImpactIn Patches>= v0.46.13 for Cosmos SDK v0.46.x >= v0.47.3 for Cosmos SDK v0.47.x If a network backported periodic vesting accounts to earlier versions of the SDK, those networks are affected too. WorkaroundsThere is no workaround for this issue. Upgrade immediately. References
Fixed in
0.46.13
0.47.3
References
Updated Nov 08, 2023 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.46.1
patch
Dependencies (55)
+ 47 more |
|
v0.46.0
minor
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-j2cr-jc39-wpx5
GHSA-w44m-8mv2-v78h
GO-2023-1861
Jul 07, 2023
Barberry Security Advisory - regarding x/auth periodic vesting accounts
Medium
ImpactIn Patches>= v0.46.13 for Cosmos SDK v0.46.x >= v0.47.3 for Cosmos SDK v0.47.x If a network backported periodic vesting accounts to earlier versions of the SDK, those networks are affected too. WorkaroundsThere is no workaround for this issue. Upgrade immediately. References
Fixed in
0.46.13
0.47.3
References
Updated Nov 08, 2023 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.46.0
minor
Dependencies (54)
+ 46 more |
|
v0.45.5
minor
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.45.5
minor
Dependencies (46)
+ 38 more |
|
v0.46.0-beta2
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.46.0-beta2
pre
Dependencies (53)
+ 45 more |
|
v0.46.0-alpha2
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.46.0-alpha2
pre
Dependencies (52)
+ 44 more |
|
v0.43.0-beta1
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.43.0-beta1
pre
Dependencies (48)
+ 40 more |
|
v0.39.3
patch
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.39.3
patch
Dependencies (26)
+ 18 more |
|
v0.42.3
minor
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.42.3
minor
Dependencies (43)
+ 35 more |
|
v0.42.0-rc0
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.42.0-rc0
pre
Dependencies (43)
+ 35 more |
|
v0.37.15
patch
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.37.15
patch
Dependencies (23)
+ 15 more |
|
v0.40.0-rc4
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.40.0-rc4
pre
Dependencies (41)
+ 33 more |
|
v0.39.1-rc2
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.39.1-rc2
pre
Dependencies (26)
+ 18 more |
|
v0.39.0
minor
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.39.0
minor
Dependencies (25)
+ 17 more |
|
v0.37.13
patch
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.37.13
patch
Dependencies (23)
+ 15 more |
|
v0.38.4
patch
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.38.4
patch
Dependencies (25)
+ 17 more |
|
v0.37.11
patch
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.37.11
patch
Dependencies (23)
+ 15 more |
|
v0.38.0
minor
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.38.0
minor
Dependencies (25)
+ 17 more |
|
v0.37.6
minor
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.37.6
minor
Dependencies (23)
+ 15 more |
|
v0.36.0-rc4
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.36.0-rc4
pre
Dependencies (23)
+ 15 more |
|
v0.34.1
minor
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.34.1
minor
Dependencies (22)
+ 14 more |
|
v0.31.2
minor
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.31.2
minor
|
|
v0.30.0
minor
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.30.0
minor
|
|
v0.30.0-dev2
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.30.0-dev2
pre
|
|
v0.29.1
patch
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.29.1
patch
|
|
v0.29.0
minor
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.29.0
minor
|
|
v0.18.0-rc1
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.18.0-rc1
pre
|
|
v0.18.0-rc0
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.18.0-rc0
pre
|
|
v0.17.4-rc0
pre
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.17.4-rc0
pre
|
|
v0.16.0
minor
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.16.0
minor
|
|
v0.2.0
initial
10 CVEs
GO-2025-3803
GHSA-p22h-3m2v-cmgh
Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk Fixed in
0.50.14
0.53.3
References Updated Jul 28, 2025 · Source: OSV.dev
GO-2025-3516
GHSA-47ww-ff84-4jrg
Mar 18, 2025
Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Cosmos SDK can halt when erroring in EndBlocker in github.com/cosmos/cosmos-sdk/ Fixed in
0.47.17
0.50.13
References Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3476
GHSA-x5vx-95h7-rv4p
Mar 03, 2025
Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Cosmos SDK: Groups module can halt chain when handling a malicious proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.16-ics-lsm
0.50.12
References Updated Mar 03, 2025 · Source: OSV.dev
GO-2024-3339
GHSA-8wcc-m6j2-qxvm
Dec 18, 2024
Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Transaction decoding may result in a stack overflow or resource exhaustion in github.com/cosmos/cosmos-sdk Fixed in
0.47.15
0.50.11
References Updated Dec 20, 2024 · Source: OSV.dev
GO-2024-2572
GHSA-4j93-fm92-rp4m
May 28, 2024
Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Missing BlockedAddressed Validation in Vesting Module in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated Jul 01, 2024 · Source: OSV.dev
GO-2024-2571
GHSA-2557-x9mg-76w8
May 22, 2024
Invalid block proposal in github.com/cosmos/cosmos-sdk Invalid block proposal in github.com/cosmos/cosmos-sdk Fixed in
0.47.9
0.50.4
References Updated May 23, 2024 · Source: OSV.dev
GO-2024-2584
GHSA-86h5-xcpx-cfqc
Mar 05, 2024
Slashing evasion in github.com/cosmos/cosmos-sdk Slashing evasion in github.com/cosmos/cosmos-sdk Fixed in
0.47.10
References Updated May 20, 2024 · Source: OSV.dev
GHSA-23px-mw2p-46qm
Sep 06, 2023
Cosmos-SDK Cosmovisor component may be vulnerable to denial of service
Medium
Component: Cosmovisor Criticality: Medium Affected Versions: Cosmovisor < v1.0.0 (distributed with Cosmos-SDK < 0.46) Affected Users: Validators and Node operators utilizing unsupported versions of Cosmovisor Impact: DOS, potential RCE on node depending on configuration An issue has been identified on unsupported versions of Cosmovisor which may result in a Denial of Service or Remote Code Execution path depending on configuration for a node or validator using the vulnerable version to manage their node. If a validator is utilizing an affected version of Cosmovisor with It is recommended that all validators utilizing unsupported versions of Cosmovisor to upgrade to the latest supported versions immediately. If you are utilizing a forked version of Cosmos-SDK, it is recommended to stop use of Cosmovisor until it is possible to update to a supported version of Cosmovisor, whether through your project’s fork, or directly compiled from the Cosmos-SDK. At the time of this advisory, the latest version of Cosmovisor is v1.5.0. Additionally, the Amulet team recommends that developers building chains powered by Cosmos-SDK share this advisory with validators and node operators to ensure this information is available to all impacted parties within their ecosystems. For more information about Cosmovisor, see https://docs.cosmos.network/main/tooling/cosmovisor This issue was discovered by Maxwell Dulin and Nathan Kirkland, who reported it to the Cosmos Bug Bounty Program. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. How to tell if I am affected?Running the following command will output whether your cosmovisor version is vulnerable to this issue or not. Vulnerable to this issue:
NOT vulnerable to this issue:
A Note from Amulet on the Security Advisory Process In the interest of timely resolution of this issue for validators and node operators, the Amulet team has chosen to use existing processes and resources for distributing security advisories within the Cosmos and Interchain Ecosystems. Stay tuned as we implement an improved, more robust security advisory distribution system that will provide equitable access to information about security issues in the Interchain Stack. Fixed in
0.46
References Updated Feb 28, 2024 · Source: OSV.dev
GO-2023-1881
GHSA-w5w5-2882-47pc
Jul 06, 2023
The x/crisis package does not charge ConstantFee in github.com/cosmos/cosmos-sdk If a transaction is sent to the x/crisis module to check an invariant, the ConstantFee parameter of the chain is not charged. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev
GO-2023-1821
GHSA-qfc5-6r3j-jj22
Jul 05, 2023
The x/crisis package does not cause chain halt in github.com/cosmos/cosmos-sdk If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended. No patch will be released, as the package is planned to be deprecated and replaced. References Updated May 20, 2024 · Source: OSV.dev |
v0.2.0
initial
|