Skip to content

Potential Denial-of-Service condition leading to temporary disability in IBC transfers to the native chain

Moderate
Zygimantass published GHSA-6fgm-x6ff-w78f Feb 12, 2025

Package

gomod github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v7 (Go)

Affected versions

<7.2.1

Patched versions

7.2.1
gomod github.com/cosmos/ibc-apps/middleware/packet-forward-middleware/v8 (Go)
<8.1.1
8.1.1

Description

Impact

Chains using affected versions of Packet Forward Middleware in their IBC Transfer stack are vulnerable to an attack in which there is a potential denial of service. This affects IBC transfers for any asset which is being transferred between another chain and its native chain.

We recommend upgrading as soon as possible.

THIS IS A STATE BREAKING CHANGE

Patches

Versions 7.2.1 and 8.1.1 are patched.

Workarounds

N/A

References

N/A

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs