-
CVSS Score
-The vulnerability stems from two key points: (1) The PoS validity predicate lacked validation for negative commission rates (CWE-248), allowing invalid state changes. (2) The update_rewards_products_and_mint_inflation function contained error-prone arithmetic (mul_floor) that couldn't handle negative values. The combination of missing validation in the validity predicate and unhandled error conditions in the inflation calculation created an uncaught exception path. The patch specifically addresses the validity predicate's validation logic, confirming its role in the vulnerability.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| namada-apps | rust | = 1.0.0 | 1.1.0 |
A Semantic Attack on Google Gemini - Read the Latest Research