github.com/cosmos/ibc-go/v4
Activity
- Latest release
- 2y ago
- Total releases
- 20
- Cadence
- ~4 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Aug 10, 2022
| Version | Released | |
|---|---|---|
v4.6.0
minor
3 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev |
v4.6.0
minor
Dependencies (19)
+ 11 more |
|
v4.5.1
patch
4 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev |
v4.5.1
patch
Dependencies (19)
+ 11 more |
|
v4.4.3
patch
4 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev |
v4.4.3
patch
Dependencies (19)
+ 11 more |
|
v4.5.0
minor
4 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev |
v4.5.0
minor
Dependencies (19)
+ 11 more |
|
v4.5.0-rc.0
pre
4 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev |
v4.5.0-rc.0
pre
Dependencies (19)
+ 11 more |
|
v4.4.2
patch
4 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev |
v4.4.2
patch
Dependencies (19)
+ 11 more |
|
v4.2.2
patch
4 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev |
v4.2.2
patch
Dependencies (19)
+ 11 more |
|
v4.1.3
patch
4 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev |
v4.1.3
patch
Dependencies (19)
+ 11 more |
|
v4.3.1
patch
4 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev |
v4.3.1
patch
Dependencies (19)
+ 11 more |
|
v4.4.1
patch
4 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev |
v4.4.1
patch
Dependencies (19)
+ 11 more |
|
v4.2.1
patch
5 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-1860
Jun 15, 2023
IBC protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. Fixed in
4.1.3
4.2.2
4.3.1
4.4.1
Updated May 20, 2024 · Source: OSV.dev |
v4.2.1
patch
Dependencies (19)
+ 11 more |
|
v4.1.2
patch
5 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-1860
Jun 15, 2023
IBC protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. Fixed in
4.1.3
4.2.2
4.3.1
4.4.1
Updated May 20, 2024 · Source: OSV.dev |
v4.1.2
patch
Dependencies (19)
+ 11 more |
|
v4.4.0
minor
5 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-1860
Jun 15, 2023
IBC protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. Fixed in
4.1.3
4.2.2
4.3.1
4.4.1
Updated May 20, 2024 · Source: OSV.dev |
v4.4.0
minor
Dependencies (19)
+ 11 more |
|
v4.3.0
minor
5 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-1860
Jun 15, 2023
IBC protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. Fixed in
4.1.3
4.2.2
4.3.1
4.4.1
Updated May 20, 2024 · Source: OSV.dev |
v4.3.0
minor
Dependencies (19)
+ 11 more |
|
v4.2.0
minor
5 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-1860
Jun 15, 2023
IBC protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. Fixed in
4.1.3
4.2.2
4.3.1
4.4.1
Updated May 20, 2024 · Source: OSV.dev |
v4.2.0
minor
Dependencies (19)
+ 11 more |
|
v4.1.1
patch
5 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-1860
Jun 15, 2023
IBC protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. Fixed in
4.1.3
4.2.2
4.3.1
4.4.1
Updated May 20, 2024 · Source: OSV.dev |
v4.1.1
patch
Dependencies (19)
+ 11 more |
|
v4.1.0
minor
5 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-1860
Jun 15, 2023
IBC protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. Fixed in
4.1.3
4.2.2
4.3.1
4.4.1
Updated May 20, 2024 · Source: OSV.dev |
v4.1.0
minor
Dependencies (19)
+ 11 more |
|
v4.0.1
patch
5 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-1860
Jun 15, 2023
IBC protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. Fixed in
4.1.3
4.2.2
4.3.1
4.4.1
Updated May 20, 2024 · Source: OSV.dev |
v4.0.1
patch
Dependencies (19)
+ 11 more |
|
v4.0.0
initial
5 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-1860
Jun 15, 2023
IBC protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. Fixed in
4.1.3
4.2.2
4.3.1
4.4.1
Updated May 20, 2024 · Source: OSV.dev |
v4.0.0
initial
Dependencies (19)
+ 11 more |
|
v4.0.0-rc3
pre
5 CVEs
GO-2025-3517
GHSA-4wf3-5qj9-368v
Mar 18, 2025
Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go Non-deterministic JSON Unmarshalling of IBC Acknowledgement can result in a chain halt in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2025-3494
GHSA-jg6f-48ff-5xrw
Mar 05, 2025
IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go IBC-Go has Non-deterministic JSON Unmarshalling of IBC Acknowledgement in github.com/cosmos/ibc-go References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2874
GHSA-qjcv-rx3v-7mvj
May 23, 2024
Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. The vulnerability allowed an attacker to send arbitrary transactions onto target chains and trigger arbitrary state transitions, including but not limited to, theft of funds. It was possible to exploit this vulnerability in specific situations involving relaying packets in which the source chain is also the final destination chain. Affected networks are those that allow for fee grant capabilities and use a native Relayer (e.g., Osmosis and Juno). References Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-2694
GHSA-j496-crgh-34mx
May 20, 2024
Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Potential Reentrancy using Timeout Callbacks in ibc-hooks in github.com/cosmos/ibc-go Fixed in
4.6.0
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2023-1860
Jun 15, 2023
IBC protocol "Huckleberry" vulnerability in github.com/cosmos/ibc-go The ibc-go module is affected by the Inter-Blockchain Communication (IBC) protocol "Huckleberry" vulnerability. Fixed in
4.1.3
4.2.2
4.3.1
4.4.1
Updated May 20, 2024 · Source: OSV.dev |
v4.0.0-rc3
pre
Dependencies (19)
+ 11 more |