CosmWasm is a smart-contract runtime and development framework for the Cosmos ecosystem, with a narrow but strategically important footprint centered on its core library and serialization components. The observed vulnerability surface clusters around access-control enforcement, integer-overflow conditions, memory-safety issues such as out-of-bounds writes, and unbounded recursion in contract execution contexts, reflecting the constraints of sandboxed execution and untrusted code interaction. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cosmwasm over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-58264HIGH The serde-json-wasm crate before 1.0.1 for Rust allows stack consumption via deeply nested JSON data. | Jul 27, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-25500HIGH An issue in CosmWasm prior to v2.2.0 allows attackers to bypass capability restrictions in blockchains by exploiting a lack of runtime capability validation. This allows attackers | Mar 18, 2025 | 7.5 | 21 | NO | NO |
CVE-2024-58263MEDIUM The cosmwasm-std crate before 2.0.2 for Rust allows integer overflows that cause incorrect contract calculations. | Jul 27, 2025 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cosmwasm.
Media articles that mention a CVE ID that affects a product developed by Cosmwasm — matched by CVE ID, not by vendor name.