Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v7
  4. ›
  5. GHSA-6fgm-x6ff-w78f

GHSA-6fgm-x6ff-w78f: Potential Denial-of-Service condition leading to temporary disability in IBC transfers to the native chain

February 12, 2025 (updated March 11, 2025)

Chains using affected versions of Packet Forward Middleware in their IBC Transfer stack are vulnerable to an attack in which there is a potential denial of service. This affects IBC transfers for any asset which is being transferred between another chain and its native chain.

We recommend upgrading as soon as possible.

THIS IS A STATE BREAKING CHANGE

References

  • github.com/advisories/GHSA-6fgm-x6ff-w78f
  • github.com/cosmos/ibc-apps
  • github.com/cosmos/ibc-apps/releases/tag/middleware%2Fpacket-forward-middleware%2Fv7.2.1
  • github.com/cosmos/ibc-apps/releases/tag/middleware%2Fpacket-forward-middleware%2Fv8.1.1
  • github.com/cosmos/ibc-apps/security/advisories/GHSA-6fgm-x6ff-w78f

Code Behaviors & Features

Detect and mitigate GHSA-6fgm-x6ff-w78f with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 7.2.1

Fixed versions

  • 7.2.1

Solution

Upgrade to version 7.2.1 or above.

Source file

go/github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v7/GHSA-6fgm-x6ff-w78f.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:36 +0000.