Low severity3.7NVD Advisory· Published Jul 27, 2025· Updated Jun 17, 2026
CVE-2024-58263
CVE-2024-58263
Description
The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cosmwasm-stdcrates.io | >= 1.3.0, < 1.4.4 | 1.4.4 |
cosmwasm-stdcrates.io | >= 1.5.0, < 1.5.4 | 1.5.4 |
cosmwasm-stdcrates.io | >= 2.0.0, < 2.0.2 | 2.0.2 |
Affected products
31.3.0+ 1 more
- (no CPE)range: 1.3.0
- cpe:2.3:a:cosmwasm:cosmwasm-std:*:*:*:*:*:rust:*:*range: >=1.3.0,<1.4.4
Patches
Vulnerability mechanics
References
8- github.com/CosmWasm/advisories/blob/main/CWAs/CWA-2024-002.mdnvdExploitPatchThird Party AdvisoryWEB
- rustsec.org/advisories/RUSTSEC-2024-0338.htmlnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-8724-5xmm-w5xqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-58263ghsaADVISORY
- crates.io/crates/cosmwasm-stdnvdProduct
- github.com/CosmWasm/cosmwasm/commit/607e7fc710fb9441096e8edbaa12879b552c8f65ghsaWEB
- github.com/CosmWasm/cosmwasm/commit/a6a639e09adc355b5f889a09141649005cb08a46ghsaWEB
- github.com/CosmWasm/cosmwasm/commit/eff79bcbe73b61178817aacf0a6449437adad6a9ghsaWEB
News mentions
0No linked articles in our index yet.