OsVault/npm/@openzeppelin/contracts
npm2 critical

@openzeppelin/contracts

18 known vulnerabilities · 2 critical · 5 high

CVE-2022-39384MEDIUM

OpenZeppelin Contracts initializer reentrancy may lead to double initialization

Published Dec 14, 2021
CVE-2023-30541MEDIUM

OpenZeppelin Contracts TransparentUpgradeableProxy clashing selector calls may not be delegated

Published Apr 17, 2023
CVE-2021-46320HIGH

Improper Initialization in OpenZeppelin

Published Feb 5, 2022
CVE-2023-30542MEDIUM

GovernorCompatibilityBravo may trim proposal calldata

Published Apr 20, 2023
CVE-2021-39167CRITICAL

TimelockController vulnerability in OpenZeppelin Contracts

Published Aug 30, 2021
CVE-2022-35961HIGH

OpenZeppelin Contracts vulnerable to ECDSA signature malleability

Published Aug 18, 2022
CVE-2022-31198HIGH

OpenZeppelin Contracts's GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals

Published Aug 18, 2022
CVE-2022-31170HIGH

OpenZeppelin Contracts's ERC165Checker may revert instead of returning false

Published Jul 21, 2022
CVE-2023-49798MEDIUM

OpenZeppelin Contracts and Contracts Upgradeable duplicated execution of subcalls in v4.9.4

Published Dec 12, 2023
CVE-2022-35915MEDIUM

OpenZeppelin Contracts ERC165Checker unbounded gas consumption

Published Aug 14, 2022
CVE-2023-26488MEDIUM

OpenZeppelin Contracts contains Incorrect Calculation

Published Mar 3, 2023
CVE-2021-41264CRITICAL

UUPSUpgradeable vulnerability in @openzeppelin/contracts

Published Sep 15, 2021
CVE-2022-31172HIGH

OpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signers

Published Jul 21, 2022
CVE-2024-27094MEDIUM

OpenZeppelin Contracts base64 encoding may read from potentially dirty memory

Published Feb 29, 2024
CVE-2023-40014MEDIUM

OpenZeppelin Contracts vulnerable to Improper Escaping of Output

Published Aug 11, 2023
CVE-2022-35916MEDIUM

OpenZeppelin Contracts's Cross chain utilities for Arbitrum L2 see EOA calls as cross chain calls

Published Aug 14, 2022
CVE-2023-34459MEDIUM

OpenZeppelin Contracts using MerkleProof multiproofs may allow proving arbitrary leaves for specific trees

Published Jun 19, 2023
CVE-2023-34234MEDIUM

OpenZeppelin Contracts's governor proposal creation may be blocked by frontrunning

Published Jun 8, 2023
Check your entire dependency tree at onceRun dependency scan →