Intel

AIKIDO-2024-10534

github.com/cosmwasm/wasmvm is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource Consumption Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 13, 2024

80

High Risk

This Affects:

gogithub.com/cosmwasm/wasmvm
0.12.0 - 1.5.4
Fixed in 1.5.5
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Uncontrolled Resource Consumption due to a flaw in the error-handling mechanism. Attackers can exploit this flaw by intentionally triggering a panic condition, leading to excessive resource utilization or a Denial of Service (DoS). This vulnerability can disrupt system availability and impact application reliability.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

github.com/cosmwasm/wasmvm is vulnerable to Uncontrolled Resource Consumption in versions 0.12.0 - 1.5.4.

How to fix this

Upgrade the github.com/cosmwasm/wasmvm library to the patch version.