-
Notifications
You must be signed in to change notification settings - Fork 3.9k
Security: cosmos/cosmos-sdk
Security Navigation
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
ISA-2025-002: x/group can halt when erroring in EndBlockerGHSA-47ww-ff84-4jrg published
Mar 12, 2025 by aljo242High -
ASA-2025-003: Groups module can halt chain when handling a malicious proposalGHSA-x5vx-95h7-rv4p published
Feb 20, 2025 by aljo242High -
ASA-2024-0012, ASA-2024-0013: CosmosSDK: Transaction decoding may result in a stack overflow or resource exhaustionGHSA-8wcc-m6j2-qxvm published
Dec 16, 2024 by julienrbrtHigh -
ASA-2024-010: cosmossdk.io/math: Mismatched bit-length validation in sdk.Int and sdk.Dec can lead to panicGHSA-7225-m954-23v7 published
Nov 20, 2024 by julienrbrtHigh -
ASA-2024-006: ValidateVoteExtensions helper function may allow incorrect voting power assumptionsGHSA-95rx-m9m5-m94v published
Mar 12, 2024 by mizmo18High -
ASA-2024-002: Default `PrepareProposalHandler` may produce invalid proposals when used with default `SenderNonceMempool`GHSA-2557-x9mg-76w8 published
Feb 20, 2024 by mizmo18Moderate -
ASA-2024-003: Missing `BlockedAddressed` Validation in Vesting ModuleGHSA-4j93-fm92-rp4m published
Feb 20, 2024 by mizmo18Moderate -
ASA-2024-005: Potential slashing evasion during re-delegationGHSA-86h5-xcpx-cfqc published
Feb 27, 2024 by mizmo18Low -
ASA-2023-001: CosmovisorGHSA-23px-mw2p-46qm published
Sep 6, 2023 by jessysaurusrexModerate -
Barberry Security Advisory - regarding x/auth periodic vesting accountsGHSA-j2cr-jc39-wpx5 published
Jul 7, 2023 by greg-szaboModerate