Low severity3.5NVD Advisory· Published Jun 6, 2024· Updated Jun 17, 2026
CVE-2024-32873
CVE-2024-32873
Description
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly when delegating vested tokens. The issue allows a clawback vesting account to anticipate the release of unvested tokens. This vulnerability is fixed in 18.0.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/evmos/evmos/v17Go | < 18.0.0 | 18.0.0 |
github.com/evmos/evmos/v16Go | < 18.0.0 | 18.0.0 |
github.com/evmos/evmos/v15Go | < 18.0.0 | 18.0.0 |
github.com/evmos/evmos/v14Go | < 18.0.0 | 18.0.0 |
github.com/evmos/evmos/v13Go | < 18.0.0 | 18.0.0 |
github.com/evmos/evmos/v12Go | < 18.0.0 | 18.0.0 |
github.com/evmos/evmos/v11Go | < 18.0.0 | 18.0.0 |
github.com/evmos/evmos/v10Go | < 18.0.0 | 18.0.0 |
github.com/evmos/evmos/v9Go | < 18.0.0 | 18.0.0 |
github.com/evmos/evmos/v8Go | < 18.0.0 | 18.0.0 |
github.com/evmos/evmos/v7Go | < 18.0.0 | 18.0.0 |
github.com/evmos/evmos/v6Go | < 18.0.0 | 18.0.0 |
Affected products
13- ghsa-coords12 versionspkg:golang/github.com/evmos/evmos/v10pkg:golang/github.com/evmos/evmos/v11pkg:golang/github.com/evmos/evmos/v12pkg:golang/github.com/evmos/evmos/v13pkg:golang/github.com/evmos/evmos/v14pkg:golang/github.com/evmos/evmos/v15pkg:golang/github.com/evmos/evmos/v16pkg:golang/github.com/evmos/evmos/v17pkg:golang/github.com/evmos/evmos/v6pkg:golang/github.com/evmos/evmos/v7pkg:golang/github.com/evmos/evmos/v8pkg:golang/github.com/evmos/evmos/v9
< 18.0.0+ 11 more
- (no CPE)range: < 18.0.0
- (no CPE)range: < 18.0.0
- (no CPE)range: < 18.0.0
- (no CPE)range: < 18.0.0
- (no CPE)range: < 18.0.0
- (no CPE)range: < 18.0.0
- (no CPE)range: < 18.0.0
- (no CPE)range: < 18.0.0
- (no CPE)range: < 18.0.0
- (no CPE)range: < 18.0.0
- (no CPE)range: < 18.0.0
- (no CPE)range: < 18.0.0
Patches
Vulnerability mechanics
References
7- github.com/evmos/evmos/commit/b2a09ca66613d8b04decd3f2dcba8e1e77709dcbnvdPatchWEB
- github.com/advisories/GHSA-pxv8-qhrh-jc7vghsaADVISORY
- github.com/evmos/evmos/security/advisories/GHSA-pxv8-qhrh-jc7vnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-32873ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-37158ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-37159ghsaADVISORY
- pkg.go.dev/vuln/GO-2024-2891ghsaWEB
News mentions
0No linked articles in our index yet.