OpenZeppelin Vulnerabilities and Affected Products
Vulnerabilities associated with openzeppelin_contracts.
Products
Clear product- openzeppelin-contracts18 vulnerabilities
- cairo-contracts3 vulnerabilities
- contracts-wizard1 vulnerability
- openzeppelin-confidential-contracts1 vulnerability
- openzeppelin-contracts-upgradeable1 vulnerability
- openzeppelin_contracts1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-40014MEDIUM | OpenZeppelin Contracts's ERC2771Context with custom forwarder may lead to zero-valued _msgSenderOpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to version 4.9.3, contracts using `ERC2771Context` along with a custom trusted forwarder may see `_msgSender` return `address(0)` in calls that originate from the forwarder with calldata shorter than 20 bytes. This combination of circumstances does not appear to be common, in particular it is not the case for `MinimalForwarder` from OpenZeppelin Contracts, or any deployed forwarder the … CWE-116Aug 10, 2023 | CVSS5.3v3.1 | EPSS0.743% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |