VDB
Sign up
CRITICAL

GHSA-h2rp-8vpx-q9r4

cheqd-node Security patch for upstream vulnerabilities in IBC-Go (ISA-2025-001) and Cosmos SDK (ISA-2025-002)

Quick fix

GHSA-h2rp-8vpx-q9r4 — github.com/cheqd/cheqd-node: upgrade to the fixed version with the command below.

go get github.com/cheqd/cheqd-node@v3.1.8

Details

# Description

There have been two upstream security advisories and associated patches published under [ISA-2025-001](https://github.com/cosmos/ibc-go/security/advisories/GHSA-4wf3-5qj9-368v) and [ISA-2025-002](https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-47ww-ff84-4jrg).

**[ISA-2025-001](https://github.com/cosmos/ibc-go/security/advisories/GHSA-4wf3-5qj9-368v)** affects the IBC-Go package., where non-deterministic JSON unmarshalling of IBC Acknowledgements can result in a chain halt.

**[ISA-2025-002](https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-47ww-ff84-4jrg)** affects the Cosmos SDK package, where `x/group` can halt when erroring in `EndBlocker`.

### Impact If unaddressed, this could result in a chain halt.

### Patches Validators, full nodes, and IBC relayers should upgrade to [cheqd-node v3.1.8](https://github.com/cheqd/cheqd-node/releases/tag/v3.1.8). This upgrade does not require a software upgrade proposal on-chain and is meant to be non state-breaking.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/cheqd/cheqd-node
Introduced in: 0Fixed in: 3.1.8
Fixgo get github.com/cheqd/cheqd-node@v3.1.8

References