Audit Open Original ↗
Ava Labs AvalancheGo
Type
Security review
Client
Ava Labs
Date
2025-08
Domain
Blockchain
Effort
10 wks
Section
Avalanche
Trail of Bits's security review of Ava Labs (Aug 2025) identified 5 issues: 5 informational.
Findings · 5
- 1 Unbounded recursion in codec allows stack overflow via deeply nested structs Informational
- 2 Lack of lower bound on range proof request bytes limit enables denial of service Informational
- 3 LevelDB prone to panic from poor construction Informational
- 4 TOCTOU in the perms package Create method Informational
- 5 API server does not limit large request body sizes Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related