{"id":"CVE-2021-41135","aliases":["GHSA-2p6r-37p9-89p2"],"title":"Authz Module Non-Determinism","summary":"Authz Module Non-Determinism","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","vendor":"cosmos","product":"github.com/cosmos/cosmos-sdk","ecosystem":"go","affected":["github.com/cosmos/cosmos-sdk >= 0.43.0, < 0.44.2"],"patched":["github.com/cosmos/cosmos-sdk 0.44.2"],"published":"2021-10-21","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-2p6r-37p9-89p2","references":[{"url":"https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-2p6r-37p9-89p2"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41135"},{"url":"https://github.com/cosmos/cosmos-sdk/commit/68ab790a761e80d3674f821794cf18ccbfed45ee"},{"url":"https://forum.cosmos.network/t/cosmos-sdk-vulnerability-retrospective-security-advisory-jackfruit-october-12-2021/5349"},{"url":"https://github.com/cosmos/cosmos-sdk"},{"url":"https://github.com/cosmos/cosmos-sdk/releases/tag/v0.44.2"}],"tags":["osv","go"],"epss":0.01713,"epssPercentile":0.76385,"ingestedAt":"2026-07-09T18:56:35.441Z","slug":"CVE-2021-41135","body":"## Overview\n\n### Impact\n\nConsensus failure for 0.43.x and 0.44.{0,1} users. \nFunds and balances are safe.\n\n### Patches\n\n0.44.2\n\n### Workarounds\n\nManually patch the code.\n\n---\n\nFull details posted in https://forum.cosmos.network/t/cosmos-sdk-vulnerability-retrospective-security-advisory-jackfruit-october-12-2021/5349.\n\n## Affected packages\n\n- `github.com/cosmos/cosmos-sdk >= 0.43.0, < 0.44.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/cosmos/cosmos-sdk 0.44.2`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}