PT-2025-40050 · Go · Github.Com/Mantra-Chain/Mantrachain+3

Publicado

2025-09-30

·

Atualizado

2025-09-30

CVSS v4.0

8.8

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N

Impact

send hooks can spend more gas than what's remained in tx, combined with recursive calls in the wasm contract, can amplify the gas consumption exponentially.

Patches

It's patched in v4.0.2 and v5.0.0

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

Correção

Allocation of Resources Without Limits

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-QWVM-WQQ8-8J69

Produtos afetados

Github.Com/Mantra-Chain/Mantrachain
Github.Com/Mantra-Chain/Mantrachain/V2
Github.Com/Mantra-Chain/Mantrachain/V3
Github.Com/Mantra-Chain/Mantrachain/V4