Skip to content

CWA-2024-003: Large address count in ValidateBasic

Low
chipshort published GHSA-m3rh-cvr5-x6q4 Aug 8, 2024

Package

gomod github.com/CosmWasm/wasmd (Go)

Affected versions

< 0.52

Patched versions

0.52

Description

Component: wasmd
Criticality: Low (ACMv1: I:Moderate; L:Unlikely)
Patched versions: wasmd 0.52.0

In multiple wasmd message types it was possible to add a large number of addresses which might lead to unexpected resource consumption in ValidateBasic.

See CWA-2024-003 for more details.

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs

Credits