#0x04

Jupiter Perpetuals: Fee Denomination Mismatch in get_close_amount()

@jbell92submitted a report toJupiterMarch 17, 2026 at 20:40
Severity
INFORMATIONAL
CVSS
8.6CVSS:3.1/AV:N/AC:L/UI:N/C:H/A:L/I:L/S:U/PR:N
Vulnerability TypeUse of Broken or Risky Cryptographic Algorithm
Asset*.jup.ag - Jupiter Domain

Description

Steps to Reproduce

Impact

Activity

@jbell92commented.
Mar 18

Your report says CVSS as not required, yet it forces one to fill it out in order to progress.

raccoons
@raccoonscommented.
Mar 18

Hi @jbell92, Thanks for your report. We are currently validating the findings and will get back to you shortly.

raccoons
@raccoonschanged the status toNeeds More Info
Mar 18

Hello @jbell92, The repository referenced in the report appears to be either inaccessible (404 error) or private: https://github.com/julianfssen/jupiter-perpetuals. Could you please provide additional information regarding this repository? How did you acquire access to this code?

@jbell92changed the status toNew
Mar 18

I was asked to resubmit under the new bug bounty program as these were with Raccoon Labs under the previous bug bounty program. I have the full mainnet cloned still. Perhaps it was merged into the main?

raccoons
@raccoonsclosed the report asInformative
Mar 20

Hi @jbell92, Thanks for clarifying. I’ve checked with our team, and we haven’t implemented any of the functions you mentioned in the code you cloned. I’m closing this report as informative. We appreciate you reaching out to report this. We look forward to more reports from you. Jupiter Security Team

@raccoonschanged the severity fromhightoinformational
Mar 23
@raccoonsdisclosed this reportPublic Disclosure
4d ago