VendorsOpenZeppelincontractsany version
Vulnerabilities

OpenZeppelin Contracts any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2021-39168
TimelockController vulnerability in OpenZeppelin Contracts
Published 2021-08-26 · Modified
10.0EPSS 0.016
CVE-2021-39167
TimelockController vulnerability in OpenZeppelin Contracts
Published 2021-08-26 · Modified
10.0EPSS 0.016
CVE-2021-41264
UUPSUpgradeable vulnerability in OpenZeppelin Contracts
Published 2021-11-12 · Modified
9.8EPSS 0.015
CVE-2023-30542
GovernorCompatibilityBravo may trim proposal calldata
Published 2023-04-16 · Modified
8.8EPSS 0.006
CVE-2022-35961
ECDSA signature malleability in OpenZeppelin Contracts
Published 2022-08-14 · Modified
7.9EPSS 0.004
CVE-2022-31170
OpenZeppelin Contracts's ERC165Checker may revert instead of returning false
Published 2022-07-21 · Modified
7.5EPSS 0.008
CVE-2022-31198
GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals in @openzeppelin/contracts
Published 2022-08-01 · Modified
7.5EPSS 0.007
CVE-2022-31172
OpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signers
Published 2022-07-21 · Modified
7.5EPSS 0.005
CVE-2024-27094
OpenZeppelin Contracts base64 encoding may read from potentially dirty memory
Published 2024-02-29 · Analyzed
7.4EPSS 0.008
CVE-2023-26488
OpenZeppelin Contracts contains Incorrect Calculation
Published 2023-03-03 · Modified
6.5EPSS 0.007
CVE-2024-45304
OwnableTwoStep allows a pending owner to accept ownership after the original owner has renounced ownership in cairo-contracts
Published 2024-08-30 · Analyzed
6.5EPSS 0.005
CVE-2023-23940
OpenZeppelin Contracts for Cairo is vulnerable to signature validation bypass
Published 2023-02-03 · Modified
6.4EPSS 0.002
CVE-2023-34459
OpenZeppelin Contracts's MerkleProof multiproofs may allow proving arbitrary leaves for specific trees
Published 2023-06-16 · Modified
5.9EPSS 0.004
CVE-2022-39384
OpenZeppelin Contracts initializer reentrancy may lead to double initialization
Published 2022-11-04 · Modified
5.6EPSS 0.005
CVE-2023-30541
TransparentUpgradeableProxy clashing selector calls may not be delegated in @openzeppelin/contracts
Published 2023-04-17 · Modified
5.3EPSS 0.008
CVE-2022-35915
Unbounded gas consumption in @openzeppelin/contracts
Published 2022-08-01 · Modified
5.3EPSS 0.008
CVE-2023-34234
Governor proposal creation may be blocked by frontrunning in OpenZeppelin
Published 2023-06-07 · Modified
5.3EPSS 0.006
CVE-2022-35916
Cross chain utilities for Arbitrum L2 see EOA calls as cross chain calls
Published 2022-08-01 · Modified
5.3EPSS 0.006