Showing 1 vulnerability on this page for openzeppelin_contracts

Signals CISA KEV Ransomware Nuclei
OpenZeppelin vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

OpenZeppelin Contracts's ERC2771Context with custom forwarder may lead to zero-valued _msgSender

OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to version 4.9.3, contracts using `ERC2771Context` along with a custom trusted forwarder may see `_msgSender` return `address(0)` in calls that originate from the forwarder with calldata shorter than 20 bytes. This combination of circumstances does not appear to be common, in particular it is not the case for `MinimalForwarder` from OpenZeppelin Contracts, or any deployed forwarder the

CWE-116Aug 10, 2023
CVSS5.3v3.1EPSS0.743%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX