Vulnerability DatabaseGHSA-x5vx-95h7-rv4p

GHSA-x5vx-95h7-rv4p
vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-x5vx-95h7-rv4p) affects the Cosmos SDK's Groups module, discovered in February 2025. This high-severity issue affects versions <= v0.47.15 and <= 0.50.11 of the Cosmos SDK, potentially impacting validators, full nodes, and users on chains utilizing the groups module (GitHub Advisory).

Technical details

The vulnerability stems from a condition where a malicious proposal could trigger a division by zero operation in the Groups module, resulting in a chain halt due to the resulting error. The issue has been assigned a high severity rating with a CVSS score of 8.7, indicating significant impact potential. The vulnerability is classified under CWE-369 (Divide By Zero) (GitHub Advisory).

Impact

The primary impact of this vulnerability is the potential for complete chain halting. Any user with access to interact with the groups module could potentially introduce this state, making it a significant threat to network availability (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in Cosmos SDK versions v0.47.16 and v0.50.12. There are no known workarounds for this issue, and it is strongly recommended that affected chains apply the update. When upgrading from affected versions, a chain upgrade is necessary to ensure that 2/3 of the validator power upgrades to the patched version (SDK Release, SDK Release).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management