Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2025-70957

A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09.
Back to all
CVE

CVE-2025-70957

A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09.

A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09. The vulnerability arises from the handling of external arguments passed to locally executed "get methods." An attacker can inject a constructed Continuation object (an internal TVM type) that is normally restricted within the VM. When the TVM executes this malicious continuation, it consumes excessive CPU resources while accruing disproportionately low virtual gas costs. This "free" computation allows an attacker to monopolize the Lite Server's processing power, significantly reducing its throughput and causing a denial of service for legitimate users acting through the gateway.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
7.5
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
C
H
U
-

Related Resources

No items found.

References

https://gist.github.com/Lucian-code233/d2589ece39914195c0e307b4dee32185, https://mp.weixin.qq.com/s/KT4RKNey_mjU2kBWpGTjuw, https://github.com/ton-blockchain/ton/commit/e35b34de22109596a54d1357dcce92d63002ba95

Severity

7.5

CVSS Score
0
10

Basic Information

Ecosystem
Base CVSS
7.5
EPSS Probability
0.00054%
EPSS Percentile
0.16749%
Introduced Version
0
Fix Available
e35b34de22109596a54d1357dcce92d63002ba95

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading