Vulnerability DatabaseGHSA-rg2q-2jh9-447q

GHSA-rg2q-2jh9-447q
Rust vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-rg2q-2jh9-447q) known as 'Gas mispricing in cosmwasm-vm' affects multiple versions of wasmvm and cosmwasm-vm packages. The issue was discovered and reported through the Cosmos Bug Bounty Program on HackerOne, with the disclosure made on July 31, 2024. The affected versions include wasmvm (< 1.5.4, >= 2.0.0 < 2.0.3, >= 2.1.0 < 2.1.2) and cosmwasm-vm (< 1.5.6, >= 2.0.0 < 2.0.5, >= 2.1.0 < 2.1.2) (CosmWasm Advisory).

Technical details

The vulnerability stems from Wasm operations consuming significantly more gas than initially indicated by benchmarks. The discrepancy between actual and expected gas consumption can be up to 10 times higher than the defined gas target. The issue has been assigned a Medium severity rating (Moderate + Likely) according to the Amulet's Severity Classification Framework. The vulnerability has a CVSS v4 base score of 5.3, with metrics indicating Network attack vector, Low attack complexity, and Low privileges required (GitHub Advisory).

Impact

The primary impact of this vulnerability is the potential for temporary Denial of Service (DoS) attacks on affected chains. Due to the gas mispricing, malicious contracts could execute operations that take approximately 10 times longer than expected, potentially disrupting normal chain operations (RustSec Advisory).

Exploitability

The vulnerability can be exploited through network access with low attack complexity and requires low privileges. No user interaction is needed for exploitation. The attack vector is accessible through the network, making it potentially exploitable by remote attackers (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in multiple versions: wasmvm (1.5.4, 2.0.3, 2.1.2) and cosmwasm-vm (1.5.7, 2.0.6, 2.1.3). Users are advised to upgrade to these patched versions. The fix involves adjusting gas prices in the cosmwasm-vm implementation. The patch is consensus-breaking and requires a coordinated upgrade (CosmWasm Advisory).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-46369HIGH7.5
  • Rust logoRust
  • nimiq-blockchain
NoYesAug 12, 2026
CVE-2026-73430MEDIUM5.3
  • Rust logoRust
  • russh
NoYesAug 12, 2026
CVE-2026-73429MEDIUM5.3
  • Rust logoRust
  • russh
NoYesAug 12, 2026
RUSTSEC-2026-0256NONEN/A
  • Rust logoRust
  • circular-buffer
NoYesAug 11, 2026
RUSTSEC-2026-0255NONEN/A
  • Rust logoRust
  • sized-chunks
NoNoAug 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management