CVE-2026-57445

Source
https://cve.org/CVERecord?id=CVE-2026-57445
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57445.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-57445
Aliases
  • GHSA-3xpr-2mm7-77j7
Published
2026-09-03T15:17:16Z
Modified
2026-10-08T03:00:13Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Gardens v2: Approve-side dispute resolution drains active streaming escrow reserve
Details

Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In dfba919e218e20d52db9f7b2e8d292d45a46c91b and prior, normal beneficiary payout paths in StreamingEscrow preserve depositAmount() while an active stream needs an escrow reserve. However, the approve-side dispute resolution path drains the whole available escrow balance to the proposal beneficiary. At time of publication, there are no publicly known patches.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-703"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57445.json"
}
References

Affected packages

Git / github.com/1hive/gardens-v2

Affected ranges

Type
GIT
Repo
https://github.com/1hive/gardens-v2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected

Affected versions

Other
contracts-uups-allowlist
contracts-uups-v0.*
contracts-uups-v0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57445.json"