github.com/tharsis/evmos
Activity
- Latest release
- 4y ago
- Total releases
- 16
- Cadence
- ~6 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Oct 07, 2021
| Version | Released | |
|---|---|---|
v1.1.3
patch
2 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.3
patch
Dependencies (24)
+ 16 more |
|
v1.1.2
patch
2 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.2
patch
Dependencies (24)
+ 16 more |
|
v1.1.1
patch
2 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.1
patch
Dependencies (24)
+ 16 more |
|
v1.1.0
minor
2 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (24)
+ 16 more |
|
v1.0.0
major
2 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.0
major
Dependencies (24)
+ 16 more |
|
v1.0.0-beta1
pre
2 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.0-beta1
pre
Dependencies (23)
+ 15 more |
|
v1.0.0-alpha1
pre
2 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.0-alpha1
pre
Dependencies (21)
+ 13 more |
|
v0.4.2
patch
3 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43839
GHSA-f854-hpxv-cw9r
Jan 06, 2022
Drainage of FeeCollector's Block Transaction Fees in cronos
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactIn Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. User funds and balances are safe. PatchesThis problem has been patched in Cronos v0.6.5 on the mempool level. The next network upgrade with consensus-breaking changes will patch it on the consensus level. WorkaroundsThere are no tested workarounds. All validator node operators are recommended to upgrade to Cronos v0.6.5 at their earliest possible convenience. CreditsThank you to @zb3 for reporting this issue on Cronos Immunefi Bug Bounty Program, to @cyril-crypto for reproducing the issue and to @yihuang and @thomas-nguy for patching the issue on the CheckTx (mempool) and the DeliverTx (consensus) levels. For more informationIf you have any questions or comments about this advisory:
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.4.2
patch
Dependencies (19)
+ 11 more |
|
v0.4.1
patch
3 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43839
GHSA-f854-hpxv-cw9r
Jan 06, 2022
Drainage of FeeCollector's Block Transaction Fees in cronos
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactIn Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. User funds and balances are safe. PatchesThis problem has been patched in Cronos v0.6.5 on the mempool level. The next network upgrade with consensus-breaking changes will patch it on the consensus level. WorkaroundsThere are no tested workarounds. All validator node operators are recommended to upgrade to Cronos v0.6.5 at their earliest possible convenience. CreditsThank you to @zb3 for reporting this issue on Cronos Immunefi Bug Bounty Program, to @cyril-crypto for reproducing the issue and to @yihuang and @thomas-nguy for patching the issue on the CheckTx (mempool) and the DeliverTx (consensus) levels. For more informationIf you have any questions or comments about this advisory:
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.4.1
patch
Dependencies (19)
+ 11 more |
|
v0.4.0
minor
3 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43839
GHSA-f854-hpxv-cw9r
Jan 06, 2022
Drainage of FeeCollector's Block Transaction Fees in cronos
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactIn Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. User funds and balances are safe. PatchesThis problem has been patched in Cronos v0.6.5 on the mempool level. The next network upgrade with consensus-breaking changes will patch it on the consensus level. WorkaroundsThere are no tested workarounds. All validator node operators are recommended to upgrade to Cronos v0.6.5 at their earliest possible convenience. CreditsThank you to @zb3 for reporting this issue on Cronos Immunefi Bug Bounty Program, to @cyril-crypto for reproducing the issue and to @yihuang and @thomas-nguy for patching the issue on the CheckTx (mempool) and the DeliverTx (consensus) levels. For more informationIf you have any questions or comments about this advisory:
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.4.0
minor
Dependencies (19)
+ 11 more |
|
v0.3.0
minor
3 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43839
GHSA-f854-hpxv-cw9r
Jan 06, 2022
Drainage of FeeCollector's Block Transaction Fees in cronos
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactIn Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. User funds and balances are safe. PatchesThis problem has been patched in Cronos v0.6.5 on the mempool level. The next network upgrade with consensus-breaking changes will patch it on the consensus level. WorkaroundsThere are no tested workarounds. All validator node operators are recommended to upgrade to Cronos v0.6.5 at their earliest possible convenience. CreditsThank you to @zb3 for reporting this issue on Cronos Immunefi Bug Bounty Program, to @cyril-crypto for reproducing the issue and to @yihuang and @thomas-nguy for patching the issue on the CheckTx (mempool) and the DeliverTx (consensus) levels. For more informationIf you have any questions or comments about this advisory:
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.3.0
minor
Dependencies (19)
+ 11 more |
|
v0.2.0
minor
3 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43839
GHSA-f854-hpxv-cw9r
Jan 06, 2022
Drainage of FeeCollector's Block Transaction Fees in cronos
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactIn Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. User funds and balances are safe. PatchesThis problem has been patched in Cronos v0.6.5 on the mempool level. The next network upgrade with consensus-breaking changes will patch it on the consensus level. WorkaroundsThere are no tested workarounds. All validator node operators are recommended to upgrade to Cronos v0.6.5 at their earliest possible convenience. CreditsThank you to @zb3 for reporting this issue on Cronos Immunefi Bug Bounty Program, to @cyril-crypto for reproducing the issue and to @yihuang and @thomas-nguy for patching the issue on the CheckTx (mempool) and the DeliverTx (consensus) levels. For more informationIf you have any questions or comments about this advisory:
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.2.0
minor
Dependencies (19)
+ 11 more |
|
v0.1.3
patch
3 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43839
GHSA-f854-hpxv-cw9r
Jan 06, 2022
Drainage of FeeCollector's Block Transaction Fees in cronos
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactIn Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. User funds and balances are safe. PatchesThis problem has been patched in Cronos v0.6.5 on the mempool level. The next network upgrade with consensus-breaking changes will patch it on the consensus level. WorkaroundsThere are no tested workarounds. All validator node operators are recommended to upgrade to Cronos v0.6.5 at their earliest possible convenience. CreditsThank you to @zb3 for reporting this issue on Cronos Immunefi Bug Bounty Program, to @cyril-crypto for reproducing the issue and to @yihuang and @thomas-nguy for patching the issue on the CheckTx (mempool) and the DeliverTx (consensus) levels. For more informationIf you have any questions or comments about this advisory:
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.1.3
patch
Dependencies (11)
+ 3 more |
|
v0.1.2
patch
3 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43839
GHSA-f854-hpxv-cw9r
Jan 06, 2022
Drainage of FeeCollector's Block Transaction Fees in cronos
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactIn Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. User funds and balances are safe. PatchesThis problem has been patched in Cronos v0.6.5 on the mempool level. The next network upgrade with consensus-breaking changes will patch it on the consensus level. WorkaroundsThere are no tested workarounds. All validator node operators are recommended to upgrade to Cronos v0.6.5 at their earliest possible convenience. CreditsThank you to @zb3 for reporting this issue on Cronos Immunefi Bug Bounty Program, to @cyril-crypto for reproducing the issue and to @yihuang and @thomas-nguy for patching the issue on the CheckTx (mempool) and the DeliverTx (consensus) levels. For more informationIf you have any questions or comments about this advisory:
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.1.2
patch
Dependencies (11)
+ 3 more |
|
v0.1.1
patch
3 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43839
GHSA-f854-hpxv-cw9r
Jan 06, 2022
Drainage of FeeCollector's Block Transaction Fees in cronos
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactIn Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. User funds and balances are safe. PatchesThis problem has been patched in Cronos v0.6.5 on the mempool level. The next network upgrade with consensus-breaking changes will patch it on the consensus level. WorkaroundsThere are no tested workarounds. All validator node operators are recommended to upgrade to Cronos v0.6.5 at their earliest possible convenience. CreditsThank you to @zb3 for reporting this issue on Cronos Immunefi Bug Bounty Program, to @cyril-crypto for reproducing the issue and to @yihuang and @thomas-nguy for patching the issue on the CheckTx (mempool) and the DeliverTx (consensus) levels. For more informationIf you have any questions or comments about this advisory:
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.1.1
patch
Dependencies (11)
+ 3 more |
|
v0.1.0
initial
3 CVEs
CVE-2022-24738
GO-2022-0348
GHSA-5jgq-x857-p8xw
Aug 21, 2024
Account compromise in Evmos in github.com/tharsis/evmos Account compromise in Evmos in github.com/tharsis/evmos References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32644
GO-2024-2715
GHSA-3fp5-2xwh-fxm6
Jun 05, 2024
Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos Evmos transaction execution not accounting for all state transition after interaction with precompiles in github.com/evmos/evmos References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43839
GHSA-f854-hpxv-cw9r
Jan 06, 2022
Drainage of FeeCollector's Block Transaction Fees in cronos
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactIn Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. User funds and balances are safe. PatchesThis problem has been patched in Cronos v0.6.5 on the mempool level. The next network upgrade with consensus-breaking changes will patch it on the consensus level. WorkaroundsThere are no tested workarounds. All validator node operators are recommended to upgrade to Cronos v0.6.5 at their earliest possible convenience. CreditsThank you to @zb3 for reporting this issue on Cronos Immunefi Bug Bounty Program, to @cyril-crypto for reproducing the issue and to @yihuang and @thomas-nguy for patching the issue on the CheckTx (mempool) and the DeliverTx (consensus) levels. For more informationIf you have any questions or comments about this advisory:
References
Updated Jul 08, 2026 · Source: OSV.dev |
v0.1.0
initial
Dependencies (11)
+ 3 more |