fuel-vm is vulnerable to Denial of Service (DoS)
35
Low Risk
The interpreter path that clears a contiguous run of storage slots must validate the span against the full key space before charging gas and touching state. Extreme combinations of a maximum-width key and a multi-slot range could wrap the end key during that validation instead of failing cleanly. The VM now rejects that class of inputs with the same panic reason used for other invalid storage range requests. Operators saw this mainly as malformed transactions failing validation rather than silent state corruption.
You are affected if you are using a version that falls within the vulnerable range.
fuel-vm is vulnerable to Denial of Service (DoS) in versions 0.66.0 - 0.66.2.
Upgrade the fuel-vm library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant