Evmos is a modestly represented blockchain platform and its associated Ethermint framework in the vulnerability landscape, yet occupies a notable position due to the criticality of its consensus and smart-contract execution layer. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and cluster around authorization and access-control flaws—including improper and incorrect authorization mechanisms and control-flow defects—that reflect the sensitivity of blockchain state validation and transaction processing. Defenders should monitor this vendor's security disclosures closely given the financial and operational impact of consensus-layer failures; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Evmos over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-32644CRITICAL Evmos is a scalable, high-throughput Proof-of-Stake EVM blockchain that is fully compatible and interoperable with Ethereum. Prior to 17.0.0, there is a way to mint arbitrary token | Apr 19, 2024 | 9.1 | 25 | NO | NO |
CVE-2022-24738HIGH Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. In versions of evmos prior to 2.0.1 attackers are able to drain unclaimed funds from user addresses. To do th | Mar 7, 2022 | 7.4 | 25 | NO | NO |
CVE-2024-39696HIGH Evmos is a decentralized Ethereum Virtual Machine chain on the Cosmos Network. Prior to version 19.0.0, a user can create a vesting account with a 3rd party account (EOA or contrac | Jul 5, 2024 | 8.1 | 24 | NO | NO |
CVE-2024-37158HIGH Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Preliminary checks on actions computed by the clawback vesting accounts are performed in the ante handler. Ev | Jun 17, 2024 | 8.1 | 21 | NO | NO |
CVE-2024-37153HIGH Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. There is an issue with how to liquid stake using Safe which itself is a contract. The bug only appears when t | Jun 6, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-37154MEDIUM Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This affects employees and grantees who have | Jun 6, 2024 | 5.3 | 20 | NO | NO |
CVE-2024-37159MEDIUM Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a validator using vested tokens to deposit the self-bond. This vu | Jun 17, 2024 | 6.5 | 18 | NO | NO |
CVE-2024-32873MEDIUM Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly when delegating vested tokens. The issue allows a clawback vest | Jun 6, 2024 | 4.3 | 15 | NO | NO |
CVE-2022-35936MEDIUM Ethermint is an Ethereum library. In Ethermint running versions before `v0.17.2`, the contract `selfdestruct` invocation permanently removes the corresponding bytecode from the int | Aug 5, 2022 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Evmos.
Media articles that mention a CVE ID that affects a product developed by Evmos — matched by CVE ID, not by vendor name.