{"id":"GHSA-82vg-5v4f-f9wq","summary":"Namada-apps can Crash with Excessive Computation in Mempool Validation","details":"### Impact\n\nA malicious transaction may cause a crash in mempool validation.\n\nA transaction with authorization section containing 256 public keys or more with valid matching signatures triggers an integer overflow in signature verification that causes a the node to panic.\n\n### Patches\n\nThis issue has been patched in apps version 1.1.0. The mempool validation has been fixed to avoid overflow.\n\n### Workarounds\n\nThere are no workarounds and users are advised to upgrade.","modified":"2025-02-20T20:33:56Z","published":"2025-02-20T20:33:56Z","database_specific":{"cwe_ids":["CWE-770"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2025-02-20T20:33:56Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/anoma/namada/security/advisories/GHSA-82vg-5v4f-f9wq"},{"type":"PACKAGE","url":"https://github.com/anoma/namada"}],"affected":[{"package":{"name":"namada-apps","ecosystem":"crates.io","purl":"pkg:cargo/namada-apps"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0"},{"fixed":"1.1.0"}]}],"versions":["1.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-82vg-5v4f-f9wq/GHSA-82vg-5v4f-f9wq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}]}