{"id":"GHSA-82vg-5v4f-f9wq","aliases":[],"url":"https://o3.security/vulnerability/GHSA-82vg-5v4f-f9wq","summary":"Namada-apps can Crash with Excessive Computation in Mempool Validation","details":"### Impact\n\nA malicious transaction may cause a crash in mempool validation.\n\nA transaction with authorization section containing 256 public keys or more with valid matching signatures triggers an integer overflow in signature verification that causes a the node to panic.\n\n### Patches\n\nThis issue has been patched in apps version 1.1.0. The mempool validation has been fixed to avoid overflow.\n\n### Workarounds\n\nThere are no workarounds and users are advised to upgrade.","published":"2025-02-20T20:33:56Z","modified":"2025-02-20T20:33:56Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"namada-apps","fixedVersion":"1.1.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/anoma/namada/security/advisories/GHSA-82vg-5v4f-f9wq"},{"type":"PACKAGE","url":"https://github.com/anoma/namada"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-02-20T20:33:56Z"}}