Skip to content

Malformed vote extensions are not rejected

Moderate
filippos47 published GHSA-2fcv-qww3-9v6h Nov 24, 2025

Package

No package listed

Affected versions

<4.1.0

Patched versions

4.1.0

Description

Summary

Adversarial validators can send large vote extensions by using non-existing protobuf tags. This will result in the rejection of the subsequent block proposal. Eventually, all block proposals will be rejected by all validators.

Impact

A small group of adversarial validators can cause a chain halt.

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs