Description
OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this operation has a bounded cost. The issue has been fixed in v4.7.2. Users are advised to upgrade. There are no known workarounds for this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6503 | OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this operation has a bounded cost. The issue has been fixed in v4.7.2. Users are advised to upgrade. There are no known workarounds for this issue. |
Github GHSA |
GHSA-7grf-83vw-6f5x | OpenZeppelin Contracts ERC165Checker unbounded gas consumption |
References
History
Wed, 23 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T17:54:51.563Z
Reserved: 2022-07-15T00:00:00.000Z
Link: CVE-2022-35915
Updated: 2024-08-03T09:44:22.215Z
Status : Modified
Published: 2022-08-01T21:15:13.687
Modified: 2024-11-21T07:11:57.170
Link: CVE-2022-35915
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA