GHSA-2fcv-qww3-9v6h
Summary
Adversarial validators can send large vote extensions by using non-existing protobuf tags. This will result in the rejection of the subsequent block proposal. Eventually, all block proposals will be rejected by all validators.
Impact
A small group of adversarial validators can cause a chain halt.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/babylonlabs-io/babylon/security/advisories/GHSA-2fcv-qww3-9v6h, https://github.com/babylonlabs-io/babylon/pull/1873/commits/86f38abd2dca5a656195a9954bb569a08d662e2b, https://github.com/babylonlabs-io/babylon, https://github.com/babylonlabs-io/babylon/releases/tag/v4.1.0
