Openzeppelin
Openzeppelin Contracts: vulnerabilidades y CVE
Openzeppelin Contracts tiene 21 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-54070 | Media (6.9) | 0.35% | — | 17 jul 2025 | OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 5.2.0 and prior to version 5.4.0, the `lastIndexOf(bytes,byte,uint256)` function of the `Bytes.sol` library may access… |
| CVE-2024-45304 | Media (6.5) | 0.48% | — | 31 ago 2024 | Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability can lead to unauthorized ownership transfer, contrary to the original owner's intention of leaving… |
| CVE-2024-27094 | Alta (7.4) | 0.76% | — | 21 mar 2024 | OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes` input by iterating over it in chunks of 3 bytes. When this input is not a multiple of 3, the last… |
| CVE-2023-49798 | Alta (7.5) | 0.54% | — | 9 dic 2023 | OpenZeppelin Contracts is a library for smart contract development. A merge issue when porting the 5.0.1 patch to the 4.9 branch caused a line duplication. In the version of `Multicall.sol` released in… |
| CVE-2023-34459 | Media (5.9) | 0.37% | — | 16 jun 2023 | OpenZeppelin Contracts is a library for smart contract development. Starting in version 4.7.0 and prior to version 4.9.2, when the `verifyMultiProof`, `verifyMultiProofCalldata`, `procesprocessMultiProof`, or… |
| CVE-2023-34234 | Media (5.3) | 0.60% | — | 7 jun 2023 | OpenZeppelin Contracts is a library for smart contract development. By frontrunning the creation of a proposal, an attacker can become the proposer and gain the ability to cancel it. The attacker can do this repeatedly… |
| CVE-2023-30541 | Media (5.3) | 0.81% | — | 17 abr 2023 | OpenZeppelin Contracts is a library for secure smart contract development. A function in the implementation contract may be inaccessible if its selector clashes with one of the proxy's own selectors. Specifically, if… |
| CVE-2023-30542 | Alta (8.8) | 0.58% | — | 16 abr 2023 | OpenZeppelin Contracts is a library for secure smart contract development. The proposal creation entrypoint (`propose`) in `GovernorCompatibilityBravo` allows the creation of proposals with a `signatures` array shorter… |
| CVE-2023-26488 | Media (6.5) | 0.71% | — | 3 mar 2023 | OpenZeppelin Contracts is a library for secure smart contract development. The ERC721Consecutive contract designed for minting NFTs in batches does not update balances when a batch has size 1 and consists of a single… |
| CVE-2023-23940 | Media (5.3) | 0.22% | — | 3 feb 2023 | OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a call to `finalize_keccak` after calling… |
| CVE-2022-39384 | Media (5.6) | 0.53% | — | 4 nov 2022 | OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initializer functions that are invoked separate from contract creation (the most prominent example being… |
| CVE-2022-35961 | Media (6.5) | 0.42% | — | 15 ago 2022 | OpenZeppelin Contracts is a library for secure smart contract development. The functions `ECDSA.recover` and `ECDSA.tryRecover` are vulnerable to a kind of signature malleability due to accepting EIP-2098 compact… |
| CVE-2022-35916 | Media (5.3) | 0.58% | — | 1 ago 2022 | OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for Arbitrum L2, `CrossChainEnabledArbitrumL2` or `LibArbitrumL2`, will classify direct interactions… |
| CVE-2022-35915 | Media (5.3) | 0.78% | — | 1 ago 2022 | OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is… |
| CVE-2022-31198 | Alta (7.5) | 0.77% | — | 1 ago 2022 | OpenZeppelin Contracts is a library for secure smart contract development. This issue concerns instances of Governor that use the module `GovernorVotesQuorumFraction`, a mechanism that determines quorum requirements as… |
| CVE-2022-31172 | Alta (7.5) | 0.49% | — | 22 jul 2022 | OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the SignatureChecker reverting. `SignatureChecker.isValidSignatureNow` is not expected to revert. However,… |
| CVE-2022-31170 | Alta (7.5) | 0.77% | — | 22 jul 2022 | OpenZeppelin Contracts is a library for smart contract development. Versions 4.0.0 until 4.7.1 are vulnerable to ERC165Checker reverting instead of returning `false`. `ERC165Checker.supportsInterface` is designed to… |
| CVE-2022-31153 | Media (6.5) | 1.4% | — | 15 jul 2022 | OpenZeppelin Contracts for Cairo is a library for contract development written in Cairo for StarkNet, a decentralized ZK Rollup. Version 0.2.0 is vulnerable to an error that renders account contracts unusable on live… |
| CVE-2021-41264 | Crítica (9.8) | 1.5% | — | 12 nov 2021 | OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. A… |
| CVE-2021-39168 | Crítica (9.8) | 1.6% | — | 27 ago 2021 | OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability… |
| CVE-2021-39167 | Crítica (9.8) | 1.6% | — | 27 ago 2021 | OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allowed an actor with the executor role to escalate privileges. Further details about the vulnerability… |