maven package report

Is org.hyperledger.besu:evm safe?

1 known vulnerability, worst severity CRITICAL.

cvss
9.1

how bad it is if exploited, out of 10

epss
1.0%

chance of exploitation in the next 30 days

xyz score
4.0

CyberXYZ composite, out of 10

fig. 01 — GHSA-4456-w38r-m53x, the advisory selected below

// advisories

GHSA-4456-w38r-m53x

CRITICALCVE-2022-36025

An error in 32 bit signed and unsigned types in the calculation of available gas in the CALL operations (including DELEGATECALL) results in incorrect gas being passed into called contracts and incorrect gas being returned after call execution. Where the amount of gas makes a difference in the success or failure, or if the gas is a negative 64 bit value, the execution will result in a different st

Affected
>= 22.4.0-RC1, < 22.7.1
Fixed in
22.7.1
Weakness
CWE-196
Published
2022-09-23
Source
github

GHSANVDMITREreference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 02:38 UTC. The most recent advisory here was published 2022-09-23. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.hyperledger.besu:evm safe? maven package security report | CyberXYZ