CVE-2022-35915
OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsInterface` query can cause unbounded gas consumption by returning a lot of data, while it is generally assumed that this operation has a bounded cost. The issue has been fixed in v4.7.2. Users are advised to upgrade. There are no known workarounds for this issue.
Published:Aug 1, 2022
Last Modified:Apr 23, 2025
EPS:Aug 1, 2022
EPSS Score:0.004
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Openzeppelin
Product
Contracts
Openzeppelin
Contracts
Vendor
Openzeppelin
Product
Contracts Upgradeable
Openzeppelin
Contracts Upgradeable
Vendor
Openzeppelin
Product
Openzeppelin-eth
Openzeppelin
Openzeppelin-eth
Vendor
Openzeppelin
Product
Openzeppelin-solidity
Openzeppelin
Openzeppelin-solidity
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
