MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4.0.1 and below do not enforce the tx gas limit in its send hooks. Send hooks can spend more gas than what remains in tx, combined with recursive calls in the wasm contract, potentially amplifying the gas consumption exponentially. This is fixed in version 4.0.2.
History

Thu, 02 Oct 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Oct 2025 19:45:00 +0000

Type Values Removed Values Added
Description MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4.0.1 and below do not enforce the tx gas limit in its send hooks. Send hooks can spend more gas than what remains in tx, combined with recursive calls in the wasm contract, potentially amplifying the gas consumption exponentially. This is fixed in version 4.0.2.
Title MANTRA tx gas limit is not enforced in send hooks
Weaknesses CWE-400
CWE-770
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-10-02T19:49:51.997Z

Reserved: 2025-09-26T16:25:25.151Z

Link: CVE-2025-61595

cve-icon Vulnrichment

Updated: 2025-10-02T19:49:48.170Z

cve-icon NVD

Status : Received

Published: 2025-10-02T20:15:35.493

Modified: 2025-10-02T20:15:35.493

Link: CVE-2025-61595

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.