CVE-2024-37159: Evmos

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a validator using vested tokens to deposit the self-bond. This vulnerability is fixed in 18.0.0.

Affected products

  • Evmos Evmos: before 18.0.0 (fixed in 18.0.0)

Published 2024-06-17. Last modified 2026-06-17.