In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerabilities in an interactive lesson.
Start learningThere is no fixed version for github.com/cosmos/cosmos-sdk/x/crisis
.
Affected versions of this package are vulnerable to Uncontrolled Resource Consumption ('Resource Exhaustion') due to improper handling of the ConstantFee
parameter when processing transactions in the x/crisis
module. An attacker can avoid paying the required fees by crafting a transaction that triggers an invariant check in the module. This allows the validator node to be spammed and can lead to an increase of the CPU usage by up to 20%.