Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/strangelove-ventures/horcrux/signer
to version 3.3.2 or higher.
Affected versions of this package are vulnerable to Race Condition in the signature state handling process. An attacker can cause the system to erroneously sign conflicting votes by sending concurrent signature requests that exploit the timing issue between read and write operations. This is only exploitable if two sign requests arrive nearly simultaneously for the same Height-Round-Step (HRS).