CVE-2022-35915: Unbounded gas consumption in @openzeppelin/contracts

Published Aug 1, 2022
·
Updated

Impact

The target contract of an EIP-165 supportsInterface query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this operation has a bounded cost.

Patches

The issue has been fixed in v4.7.2.

References

https://github.com/OpenZeppelin/openzeppelin-contracts/pull/3587

For more information

If you have any questions or comments about this advisory, or need assistance deploying a fix, email us at security@openzeppelin.com.

Other sources

OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 supportsInterface query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this operation has a bounded cost. The issue has been fixed in v4.7.2. Users are advised to upgrade. There are no known workarounds for this issue.

Affected Software

8 affected componentsFixes available
npm/openzeppelin-eth>=2.0.0<=2.2.0
npm/@openzeppelin/contracts-upgradeable>=3.2.0<4.7.2
4.7.2
npm/openzeppelin-solidity>=2.0.0<=4.6.0
npm/@openzeppelin/contracts>=2.0.0<4.7.2
4.7.2
OpenZeppelin Contracts Node.js>=2.0.0<4.7.2
OpenZeppelin Contracts Upgradeable Node.js>=3.2.0<4.7.2
OpenZeppelin Openzeppelin-eth Node.js>=2.0.0
OpenZeppelin Openzeppelin-solidity Node.js>=2.0.0

Event History

Aug 1, 2022
CVE Published
via MITRE·09:05 PM
Data Sourced
via MITRE·09:05 PM
DescriptionSeverityWeakness
Aug 14, 2022
Advisory Published
12:23 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the impact of CVE-2022-35915?

The target contract of an EIP-165 supportsInterface query can cause unbounded gas consumption by returning a lot of data.

2

Which versions of OpenZeppelin Contracts are affected by CVE-2022-35915?

OpenZeppelin Contracts versions 2.0.0 to 4.7.2 are affected.

3

How can I fix CVE-2022-35915 in my OpenZeppelin Contracts library?

Upgrade to version 4.7.2 of OpenZeppelin Contracts.

4

Where can I find more information about CVE-2022-35915?

You can find more information about CVE-2022-35915 in the OpenZeppelin Contracts security advisory or the NVD.

5

What is the severity rating of CVE-2022-35915?

The severity rating of CVE-2022-35915 is medium (5.3).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203