Openzeppelin-Contracts
OpenZeppelin · 18 CVEs
OpenZeppelin Contracts's Bytes's lastIndexOf function with position argument performs out-of-bound memory access on emp…
Jul 17, 2025
OpenZeppelin Contracts base64 encoding may read from potentially dirty memory
Feb 29, 2024
Duplicated execution of subcalls in OpenZeppelin Contracts
Dec 8, 2023
OpenZeppelin Contracts's ERC2771Context with custom forwarder may lead to zero-valued _msgSender
Aug 10, 2023
OpenZeppelin Contracts's MerkleProof multiproofs may allow proving arbitrary leaves for specific trees
Jun 16, 2023
Governor proposal creation may be blocked by frontrunning in OpenZeppelin
Jun 7, 2023
TransparentUpgradeableProxy clashing selector calls may not be delegated in @openzeppelin/contracts
Apr 17, 2023
GovernorCompatibilityBravo may trim proposal calldata
Apr 16, 2023
OpenZeppelin Contracts contains Incorrect Calculation
Mar 3, 2023
OpenZeppelin Contracts initializer reentrancy may lead to double initialization
Nov 4, 2022
ECDSA signature malleability in OpenZeppelin Contracts
Aug 14, 2022
Unbounded gas consumption in @openzeppelin/contracts
Aug 1, 2022
Cross chain utilities for Arbitrum L2 see EOA calls as cross chain calls
Aug 1, 2022
GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals in @openzeppelin/contracts
Aug 1, 2022
OpenZeppelin Contracts's ERC165Checker may revert instead of returning false
Jul 21, 2022
OpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signers
Jul 21, 2022
UUPSUpgradeable vulnerability in OpenZeppelin Contracts
Nov 12, 2021
TimelockController vulnerability in OpenZeppelin Contracts
Aug 26, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-54070 | OpenZeppelin Contracts's Bytes's lastIndexOf function with position argument performs out-of-bound memory access on empty buffers | MEDIUM | 0.35% | Jul 17, 2025 |
| CVE-2024-27094 | OpenZeppelin Contracts base64 encoding may read from potentially dirty memory | HIGH | 0.76% | Feb 29, 2024 |
| CVE-2023-49798 | Duplicated execution of subcalls in OpenZeppelin Contracts | HIGH | 0.54% | Dec 8, 2023 |
| CVE-2023-40014 | OpenZeppelin Contracts's ERC2771Context with custom forwarder may lead to zero-valued _msgSender | MEDIUM | 0.74% | Aug 10, 2023 |
| CVE-2023-34459 | OpenZeppelin Contracts's MerkleProof multiproofs may allow proving arbitrary leaves for specific trees | MEDIUM | 0.37% | Jun 16, 2023 |
| CVE-2023-34234 | Governor proposal creation may be blocked by frontrunning in OpenZeppelin | MEDIUM | 0.60% | Jun 7, 2023 |
| CVE-2023-30541 | TransparentUpgradeableProxy clashing selector calls may not be delegated in @openzeppelin/contracts | MEDIUM | 0.81% | Apr 17, 2023 |
| CVE-2023-30542 | GovernorCompatibilityBravo may trim proposal calldata | HIGH | 0.58% | Apr 16, 2023 |
| CVE-2023-26488 | OpenZeppelin Contracts contains Incorrect Calculation | MEDIUM | 0.71% | Mar 3, 2023 |
| CVE-2022-39384 | OpenZeppelin Contracts initializer reentrancy may lead to double initialization | MEDIUM | 0.53% | Nov 4, 2022 |
| CVE-2022-35961 | ECDSA signature malleability in OpenZeppelin Contracts | HIGH | 0.42% | Aug 14, 2022 |
| CVE-2022-35915 | Unbounded gas consumption in @openzeppelin/contracts | MEDIUM | 0.78% | Aug 1, 2022 |
| CVE-2022-35916 | Cross chain utilities for Arbitrum L2 see EOA calls as cross chain calls | MEDIUM | 0.58% | Aug 1, 2022 |
| CVE-2022-31198 | GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals in @openzeppelin/contracts | HIGH | 0.77% | Aug 1, 2022 |
| CVE-2022-31170 | OpenZeppelin Contracts's ERC165Checker may revert instead of returning false | HIGH | 0.77% | Jul 21, 2022 |
| CVE-2022-31172 | OpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signers | HIGH | 0.49% | Jul 21, 2022 |
| CVE-2021-41264 | UUPSUpgradeable vulnerability in OpenZeppelin Contracts | CRITICAL | 1.49% | Nov 12, 2021 |
| CVE-2021-39167 | TimelockController vulnerability in OpenZeppelin Contracts | CRITICAL | 1.59% | Aug 26, 2021 |
Showing 1 to 18 of 18 CVEs