mediumLogic errorCosmos-SDK
Allora: Malicious peer can cause a syncing node to panic during blocksync
- Payout
- $0
- Protocol
- Allora
- Disclosed
- Jul 19, 2024
- Source
- sherlock
Allora's allora-chain pinned CometBFT v0.38.6, which carries the blocksync denial-of-service weakness tracked as GO-2024-2951. Because node startup routes through cmd.Execute down into the blocksync reactor paths (BlockPool.OnStart, Reactor.Receive, SwitchToBl …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.