github.com/Cosmos/ibc-go/v7 is vulnerable to Expected Behavior Violation
99
Critical Risk
Affected versions of this package are vulnerable to non-deterministic JSON unmarshalling in IBC acknowledgements, which can cause a chain halt. This issue affects IBC-Go versions >= v7 and potentially earlier versions. Any user capable of opening an IBC channel can trigger this vulnerability, leading to network disruption. The latest patch extends protections to all applications beyond transfer.
You are affected if you are using a version that falls within the vulnerable range.
github.com/Cosmos/ibc-go/v7 is vulnerable to Expected Behavior Violation in versions 7.0.0 - 7.9.2.
Upgrade the github.com/Cosmos/ibc-go/v8 library to the patch version. To prevent this state from being introduced to a chain, it is possible to permission Channel Opening as a workaround.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant