{"id":"GHSA-p22h-3m2v-cmgh","aliases":["GO-2025-3803"],"url":"https://o3.security/vulnerability/GHSA-p22h-3m2v-cmgh","summary":"Cosmos SDK's Integer Overflow vulnerability in its Validator Rewards pool can cause a chain halt","details":"Description\nName: ISA-2025-005: Integer Overflow in Cosmos SDK\nComponent: CosmosSDK\nCriticality: High (Considerable Impact; Likely Likelihood per [ACMv1.2](https://github.com/interchainio/security/blob/main/resources/CLASSIFICATION_MATRIX.md))\nAffected versions: <= v0.50.13, <= 0.53.2\nAffected users: Validators, Full nodes, Users on chains that utilize the distribution module\nCosmos SDK chains in unpatched releases that use the x/distribution module are affected.\n\nDescription\nAn issue was discovered in the distribution module where a malicious deposit into the Validator Rewards pool would result in an integer overflow that would cause a chain halt. A malicious validator can interact with the distribution module to introduce this state.\n\nPatches\nHas the problem been patched? What versions should users upgrade to?\n\nThe new Cosmos SDK release [v0.50.14](https://github.com/cosmos/cosmos-sdk/releases/tag/v0.50.14) and [v0.53.3](https://github.com/cosmos/cosmos-sdk/releases/tag/v0.53.3) fix this issue.\n\nThere are no known workarounds for this issue. It is advised that chains apply the update.\n\nThis issue was reported to the Cosmos Bug Bounty Program by `myte1111111` on HackerOne on April 15, 2025. If you believe you have found a bug in the Interchain Stack or would like to contribute to the program by reporting a bug, please see https://hackerone.com/cosmos.\n\nIf you have questions about Interchain security efforts, please reach out to our official communication channel at [security@interchain.io](mailto:security@interchain.io). For more information about the Interchain Foundation’s engagement with Amulet, and to sign up for security notification emails, please see https://github.com/interchainio/security.","published":"2025-07-08T23:33:08Z","modified":"2025-07-28T20:42:20.908326Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/cosmos/cosmos-sdk","fixedVersion":"0.50.14"},{"ecosystem":"Go","name":"github.com/cosmos/cosmos-sdk","fixedVersion":"0.53.3"}],"fix":{"url":"https://github.com/cosmos/cosmos-sdk/commit/c4a14fa7b6828432fdabdb8b4af68ade9403ce49","label":"cosmos/cosmos-sdk@c4a14fa"},"references":[{"type":"WEB","url":"https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-p22h-3m2v-cmgh"},{"type":"WEB","url":"https://github.com/cosmos/cosmos-sdk/commit/c4a14fa7b6828432fdabdb8b4af68ade9403ce49"},{"type":"WEB","url":"https://github.com/cosmos/cosmos-sdk/commit/f2e6295b662fdb27ea33da1296c29588ccdaab42"},{"type":"PACKAGE","url":"https://github.com/cosmos/cosmos-sdk"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-07-28T20:42:20.908326Z"}}