
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (GHSA-rg2q-2jh9-447q) known as 'Gas mispricing in cosmwasm-vm' affects multiple versions of wasmvm and cosmwasm-vm packages. The issue was discovered and reported through the Cosmos Bug Bounty Program on HackerOne, with the disclosure made on July 31, 2024. The affected versions include wasmvm (< 1.5.4, >= 2.0.0 < 2.0.3, >= 2.1.0 < 2.1.2) and cosmwasm-vm (< 1.5.6, >= 2.0.0 < 2.0.5, >= 2.1.0 < 2.1.2) (CosmWasm Advisory).
The vulnerability stems from Wasm operations consuming significantly more gas than initially indicated by benchmarks. The discrepancy between actual and expected gas consumption can be up to 10 times higher than the defined gas target. The issue has been assigned a Medium severity rating (Moderate + Likely) according to the Amulet's Severity Classification Framework. The vulnerability has a CVSS v4 base score of 5.3, with metrics indicating Network attack vector, Low attack complexity, and Low privileges required (GitHub Advisory).
The primary impact of this vulnerability is the potential for temporary Denial of Service (DoS) attacks on affected chains. Due to the gas mispricing, malicious contracts could execute operations that take approximately 10 times longer than expected, potentially disrupting normal chain operations (RustSec Advisory).
The vulnerability can be exploited through network access with low attack complexity and requires low privileges. No user interaction is needed for exploitation. The attack vector is accessible through the network, making it potentially exploitable by remote attackers (GitHub Advisory).
The vulnerability has been patched in multiple versions: wasmvm (1.5.4, 2.0.3, 2.1.2) and cosmwasm-vm (1.5.7, 2.0.6, 2.1.3). Users are advised to upgrade to these patched versions. The fix involves adjusting gas prices in the cosmwasm-vm implementation. The patch is consensus-breaking and requires a coordinated upgrade (CosmWasm Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."