SecAlerts
o

openzeppelin

Security Risk Profile

27
/100
low

Security Risk Score

Comprehensive risk assessment based on 26 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from August 26, 2021 to present

26
Total CVEs
11
Critical+High
0
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
27/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
3
High
8
Medium
13
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
Input Validation
3
2
Code Injection
1
3
Integer Overflow
1

Most Affected Products

1. OpenZeppelin Contracts Node.js20
2. OpenZeppelin Contracts Upgradeable Node.js13
3. npm/@openzeppelin/contracts-upgradeable9
4. npm/@openzeppelin/contracts9
5. OpenZeppelin Contracts Cairo3

Recent Vulnerabilities

See more →
CVE-2026-57583
CVSS 3.3low

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

Sep 14, 2026🔧 No Patch
CVE-2026-73645
CVSS 6.6medium

OpenZeppelin Confidential Contracts ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not revert and result in loss of funds.

Aug 13, 2026🔧 No Patch
CVE-2025-54070
CVSS 6.9medium

OpenZeppelin Contracts's Bytes's lastIndexOf function with position argument performs out-of-bound memory access on empty buffers

Jul 17, 2025
CVE-2024-45304
CVSS 6.5medium

OwnableTwoStep allows a pending owner to accept ownership after the original owner has renounced ownership in cairo-contracts

Aug 30, 2024
CVE-2024-27094
CVSS 7.4EPSS 0%high

OpenZeppelin Contracts base64 encoding may read from potentially dirty memory

Feb 29, 2024
CVE-2023-49798
CVSS 7.5high

Duplicated execution of subcalls in OpenZeppelin Contracts

Dec 8, 2023
https://www.bleepingcomputer.com/news/security/multiple-nft-collections-at-risk-by-flaw-in-open-source-library/
unknown

Multiple NFT collections at risk by flaw in open-source library

Dec 5, 2023🔧 No Patch
CVE-2023-40014
CVSS 5.3medium

OpenZeppelin Contracts's ERC2771Context with custom forwarder may lead to zero-valued _msgSender

Aug 10, 2023
CVE-2023-34459
CVSS 5.9medium

OpenZeppelin Contracts's MerkleProof multiproofs may allow proving arbitrary leaves for specific trees

Jun 16, 2023
CVE-2023-34234
CVSS 5.3medium

Governor proposal creation may be blocked by frontrunning in OpenZeppelin

Jun 7, 2023

Monitor openzeppelin in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

openzeppelin Security Vulnerabilities & Risk Score | 26 CVEs | SecAlerts - SecAlerts