github.com/cosmwasm/wasmvm is vulnerable to Incorrect Calculation
55
Medium Risk
Affected versions of this package are vulnerable to incorrect calculation due to flaws in the metering logic. These flaws allow attackers to manipulate the execution of smart contracts by exploiting the inaccurate resource metering mechanism. As a result, the package fails to properly account for resource consumption, enabling attackers to bypass limits or other security issues within the smart contract ecosystem.
You are affected if you are using a vulnerable version of the package.
github.com/cosmwasm/wasmvm is vulnerable to Incorrect Calculation in versions 0.12.0 - 1.5.4.
Upgrade the github.com/cosmwasm/wasmvm library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant