Vulnerability DatabaseGHSA-869w-47c6-fq8q

GHSA-869w-47c6-fq8q
vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-869w-47c6-fq8q) affects the Babylon blockchain platform's distribution module, specifically in the CumulativeRewardRatio calculation functionality. The issue was discovered and published on May 13, 2025, affecting versions <= 1.0.2 of the babylonlabs-io/babylon package (GitHub Advisory).

Technical details

The vulnerability stems from an integer overflow condition in the distribution module's CumulativeRewardRatio calculation. The issue manifests when processing large token amounts that are transferred through IBC and subsequently deposited in the validator rewards pool using the DepositValidatorRewardsPool message. The calculation occurs in the x/epoching module EndBlocker. The vulnerability has been assigned a CVSS v4 score of 8.2 (High), with attack vector being Network, attack complexity Low, and no privileges or user interaction required (GitHub Advisory).

Impact

The primary impact of this vulnerability is a Denial of Service condition affecting the Babylon Genesis chain. When the integer overflow occurs during the CumulativeRewardRatio calculation, it triggers a panic in the EndBlocker, which results in a complete halt of the blockchain (GitHub Advisory).

Mitigation and workarounds

A patch has been released in version 1.1.0 of the babylonlabs-io/babylon package. Users are advised to upgrade to this version to mitigate the vulnerability (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management