alloy-eips is vulnerable to Integer Overflow
25
Low Risk
Affected versions of this package are vulnerable to an integer overflow in the fake_exponential function, which is used to calculate blob gas prices per EIP-4844. The vulnerability occurs when numerator_accum * numerator exceeds u128::MAX, causing the function to panic on arithmetic overflow. This can be triggered by processing blocks with intentionally invalid excess blob gas values near u64::MAX, potentially leading to denial of service.
You are affected if you are using a version that falls within the vulnerable range and you are using Windows.
alloy-eips is vulnerable to Integer Overflow in versions 0.0.1 - 1.0.25.
Upgrade the alloy-eips library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant