github.com/cosmwasm/wasmvm
Go bindings to the CosmWasm VM
Activity
- Latest release
- 1y ago
- Total releases
- 20
- Cadence
- ~14 days
- Last 12 months
- 0
Reach
- Stars
- 205
Details
- First release
- Jul 05, 2023
| Version | Released | |
|---|---|---|
v1.5.9
patch
|
v1.5.9
patch
Dependencies (2)
|
|
v1.5.8
patch
|
v1.5.8
patch
Dependencies (2)
|
|
v1.5.7
patch
2 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.7
patch
Dependencies (2)
|
|
v1.5.6
patch
2 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.6
patch
Dependencies (2)
|
|
v1.5.5
patch
2 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.5
patch
Dependencies (2)
|
|
v1.5.4
patch
4 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev |
v1.5.4
patch
Dependencies (2)
|
|
v1.5.3
patch
5 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.5.3
patch
Dependencies (2)
|
|
v1.5.2
patch
5 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.5.2
patch
Dependencies (2)
|
|
v1.4.3
patch
5 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.4.3
patch
Dependencies (2)
|
|
v1.5.2-rc.0
pre
5 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.5.2-rc.0
pre
Dependencies (2)
|
|
v1.3.1
patch
5 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.3.1
patch
Dependencies (2)
|
|
v1.4.2
patch
5 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.4.2
patch
Dependencies (2)
|
|
v1.5.1
patch
5 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.5.1
patch
Dependencies (2)
|
|
v1.5.0
minor
6 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-3101
GHSA-75qh-gg76-p2w4
RUSTSEC-2024-0366
Dec 20, 2024
Excessive number of function parameters in compiled Wasm in github.com/CosmWasm/wasmvm A specifically crafted Wasm file can cause the VM to consume excessive amounts of memory when compiling a contract. This can lead to high memory usage, slowdowns, potentially a crash and can poison a lock in the VM, preventing any further interaction with contracts. Fixed in
1.2.5
1.3.1
1.4.2
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.5.0
minor
Dependencies (2)
|
|
v1.5.0-rc.0
pre
5 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.5.0-rc.0
pre
Dependencies (2)
|
|
v1.4.1
patch
6 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-3101
GHSA-75qh-gg76-p2w4
RUSTSEC-2024-0366
Dec 20, 2024
Excessive number of function parameters in compiled Wasm in github.com/CosmWasm/wasmvm A specifically crafted Wasm file can cause the VM to consume excessive amounts of memory when compiling a contract. This can lead to high memory usage, slowdowns, potentially a crash and can poison a lock in the VM, preventing any further interaction with contracts. Fixed in
1.2.5
1.3.1
1.4.2
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.4.1
patch
Dependencies (2)
|
|
v1.4.0
minor
6 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-3101
GHSA-75qh-gg76-p2w4
RUSTSEC-2024-0366
Dec 20, 2024
Excessive number of function parameters in compiled Wasm in github.com/CosmWasm/wasmvm A specifically crafted Wasm file can cause the VM to consume excessive amounts of memory when compiling a contract. This can lead to high memory usage, slowdowns, potentially a crash and can poison a lock in the VM, preventing any further interaction with contracts. Fixed in
1.2.5
1.3.1
1.4.2
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.4.0
minor
Dependencies (2)
|
|
v1.4.0-rc.1
pre
5 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.4.0-rc.1
pre
Dependencies (2)
|
|
v1.3.0
initial
6 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GO-2024-3101
GHSA-75qh-gg76-p2w4
RUSTSEC-2024-0366
Dec 20, 2024
Excessive number of function parameters in compiled Wasm in github.com/CosmWasm/wasmvm A specifically crafted Wasm file can cause the VM to consume excessive amounts of memory when compiling a contract. This can lead to high memory usage, slowdowns, potentially a crash and can poison a lock in the VM, preventing any further interaction with contracts. Fixed in
1.2.5
1.3.1
1.4.2
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.3.0
initial
Dependencies (2)
|
|
v1.3.0-rc.0
pre
5 CVEs
GO-2025-3448
GHSA-23qp-3c2m-xx6w
Feb 05, 2025
Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Malicious smart contract can crash the chain in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 18, 2025 · Source: OSV.dev
GO-2025-3449
GHSA-mx2j-7cmv-353c
Feb 05, 2025
wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm wasmvm: Malicious smart contract can slow down block production in github.com/CosmWasm/wasmvm Fixed in
1.5.8
References
Updated Mar 03, 2026 · Source: OSV.dev
GHSA-2q97-m5rc-p3gp
Dec 10, 2024
CosmWasm VM Incorrect metering
Medium
CWA-2024-007Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-vmqh-5232-v43r
Dec 10, 2024
Panic in wasmvm can slow down block production
Medium
CWA-2024-008Severity Medium (Moderate + Likely)[^1] Affected versions:
Patched versions:
Description of the bug(Blank for now. We'll add more detail once chains had a chance to upgrade.) Patch
Applying the patchThe patch will be shipped in releases of wasmvm. You can update more or less as follows:
To double check if the correct library version is loaded at runtime, use this query:
The patch is consensus breaking and requires a coordinated upgrade. AcknowledgementThis issue was found by meadow101 who reported it to the Cosmos Bug Bounty Program on HackerOne. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos. Timeline
[^1]: following Amulet's Severity Classification Framework ACMv1: https://github.com/interchainio/security/blob/e0227a1fb4059144aab4f6003eeee7f09912db3a/resources/CLASSIFICATION_MATRIX.md Fixed in
1.5.5
References
Updated Dec 10, 2024 · Source: OSV.dev
GHSA-rg2q-2jh9-447q
RUSTSEC-2024-0361
Aug 08, 2024
Gas mispricing in cosmwasm-vm
Medium
Network
Low
Low
None
Component: wasmvm Criticality: Medium (ACMv1: I:Moderate; L:Likely) Patched versions: wasmvm 1.5.4, 2.0.3, 2.1.2 Some Wasm operations take significantly more gas than our benchmarks indicated. This can lead to missing the gas target we defined by a factor of ~10x. This means a malicious contract could take 10 times as much time to execute as expected, which can be used to temporarily DoS a chain. See CWA-2024-004 for more details. Fixed in
1.5.4
References
Updated Aug 08, 2024 · Source: OSV.dev |
v1.3.0-rc.0
pre
Dependencies (2)
|