
@openzeppelin/contracts
Secure Smart Contract library for Solidity
Security Advisories for @openzeppelin/contracts in npm
Moderate
3 months ago
OpenZeppelin Contracts Bytes's lastIndexOf function with position argument performs out-of-bound memory access on empty buffers
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Low
over 1 year ago
OpenZeppelin Contracts base64 encoding may read from potentially dirty memory
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Moderate
almost 2 years ago
OpenZeppelin Contracts and Contracts Upgradeable duplicated execution of subcalls in v4.9.4
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Moderate
about 2 years ago
OpenZeppelin Contracts vulnerable to Improper Escaping of Output
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Moderate
over 2 years ago
OpenZeppelin Contracts using MerkleProof multiproofs may allow proving arbitrary leaves for specific trees
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Moderate
over 2 years ago
OpenZeppelin Contracts's governor proposal creation may be blocked by frontrunning
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
High
over 2 years ago
GovernorCompatibilityBravo may trim proposal calldata
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Moderate
over 2 years ago
OpenZeppelin Contracts TransparentUpgradeableProxy clashing selector calls may not be delegated
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Moderate
over 2 years ago
OpenZeppelin Contracts contains Incorrect Calculation
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
High
about 3 years ago
OpenZeppelin Contracts vulnerable to ECDSA signature malleability
npm
@openzeppelin/contracts
High
about 3 years ago
OpenZeppelin Contracts's GovernorVotesQuorumFraction updates to quorum may affect past defeated proposals
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Moderate
about 3 years ago
OpenZeppelin Contracts's Cross chain utilities for Arbitrum L2 see EOA calls as cross chain calls
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Moderate
about 3 years ago
OpenZeppelin Contracts ERC165Checker unbounded gas consumption
npm
openzeppelin-eth, @openzeppelin/contracts-upgradeable, openzeppelin-solidity, @openzeppelin/contracts
High
about 3 years ago
OpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signers
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
High
about 3 years ago
OpenZeppelin Contracts's ERC165Checker may revert instead of returning false
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Moderate
over 3 years ago
GovernorCompatibilityBravo incorrect ABI encoding may lead to unexpected behavior
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Moderate
almost 4 years ago
OpenZeppelin Contracts initializer reentrancy may lead to double initialization
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Low
almost 4 years ago
ERC1155Supply vulnerability in OpenZeppelin Contracts
npm
@openzeppelin/contracts-upgradeable, @openzeppelin/contracts
Critical
about 4 years ago
UUPSUpgradeable vulnerability in @openzeppelin/contracts
npm
@openzeppelin/contracts
Critical
about 4 years ago
TimelockController vulnerability in OpenZeppelin Contracts
npm
@openzeppelin/contracts