If an invariant check fails on a Cosmos SDK network, and a transaction is sent to the x/crisis package to halt the chain, the chain does not halt as originally intended.
No patch will be released, as the package is planned to be deprecated and replaced.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2023-1821" }