Vulnerability Report: GO-2025-3803
- GHSA-p22h-3m2v-cmgh
- Affects: github.com/cosmos/cosmos-sdk
- Published: Jul 28, 2025
Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt in github.com/cosmos/cosmos-sdk
For detailed information about this vulnerability, visit https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-p22h-3m2v-cmgh.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.50.14, from v0.52.0-alpha.1 before v0.53.3
1 unexported affected symbols
- msgServer.DepositValidatorRewardsPool
Aliases
References
- https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-p22h-3m2v-cmgh
- https://github.com/cosmos/cosmos-sdk/commit/c4a14fa7b6828432fdabdb8b4af68ade9403ce49
- https://github.com/cosmos/cosmos-sdk/commit/f2e6295b662fdb27ea33da1296c29588ccdaab42
- https://vuln.go.dev/ID/GO-2025-3803.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.