CVE-2026-28410

Source
https://cve.org/CVERecord?id=CVE-2026-28410
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28410.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-28410
Aliases
  • GHSA-qx35-rc5x-x39r
Published
2026-03-05T20:11:54.254Z
Modified
2026-04-10T05:42:22.542Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
The Graph: Revocable vesting contracts allows early access to locked tokens
Details

The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the token vesting contracts allows users to access tokens that should still be locked according to their vesting schedule. This issue has been patched in version 3.0.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-284",
        "CWE-682"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28410.json"
}
References

Affected packages

Git / github.com/graphprotocol/contracts

Affected ranges

Type
GIT
Repo
https://github.com/graphprotocol/contracts
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other
audit/n06
l2-deploy-commit
v0.*
v0.1.1
v0.1.2
v0.2.0
v0.3.0-beta
v0.3.1-beta
v0.4.5-testnet-phase1
v0.4.6-testnet-phase1
v0.4.7-testnet-phase1
v0.4.8-testnet-phase1
v0.4.9-testnet-phase1
v0.5.0-testnet-phase1
v0.6.0-audit
v1.*
v1.0.0
v1.10.0
v1.10.1
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.12.0
v1.13.0
v1.14.0
v1.16.0
v1.17.0
v1.2.0
v1.3.0
v1.4.0
v1.5.0
v1.6.0
v1.7.0
v1.8.0
v1.9.0
v2.*
v2.1.0
v2.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28410.json"