{"id":"GHSA-2p6r-37p9-89p2","summary":"Authz Module Non-Determinism","details":"### Impact\n\nConsensus failure for 0.43.x and 0.44.{0,1} users. \nFunds and balances are safe.\n\n### Patches\n\n0.44.2\n\n### Workarounds\n\nManually patch the code.\n\n---\n\nFull details posted in https://forum.cosmos.network/t/cosmos-sdk-vulnerability-retrospective-security-advisory-jackfruit-october-12-2021/5349.","aliases":["CVE-2021-41135"],"modified":"2026-07-08T06:28:41.904459282Z","published":"2021-10-21T17:46:57Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-10-20T15:36:34Z","nvd_published_at":"2021-10-20T18:15:00Z","cwe_ids":["CWE-754"]},"references":[{"type":"WEB","url":"https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-2p6r-37p9-89p2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41135"},{"type":"WEB","url":"https://github.com/cosmos/cosmos-sdk/commit/68ab790a761e80d3674f821794cf18ccbfed45ee"},{"type":"WEB","url":"https://forum.cosmos.network/t/cosmos-sdk-vulnerability-retrospective-security-advisory-jackfruit-october-12-2021/5349"},{"type":"PACKAGE","url":"https://github.com/cosmos/cosmos-sdk"},{"type":"WEB","url":"https://github.com/cosmos/cosmos-sdk/releases/tag/v0.44.2"}],"affected":[{"package":{"name":"github.com/cosmos/cosmos-sdk","ecosystem":"Go","purl":"pkg:golang/github.com/cosmos/cosmos-sdk"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.43.0"},{"fixed":"0.44.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-2p6r-37p9-89p2/GHSA-2p6r-37p9-89p2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}