CVE-2024-27094

    Dashboard / Vulnerabilities / CVE-2024-27094

    CVE-2024-27094

    Published: 29 Feb 2024Last Modified: 12 Aug 2026

    Summary: OpenZeppelin Contracts base64 encoding may read from potentially dirty memory

    Details: OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes` input by iterating over it in chunks of 3 bytes. When this input is not a multiple of 3, the last iteration may read parts of the memory that are beyond the input buffer. The vulnerability is fixed in 5.0.2 and 4.9.6.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- a5445b0afb8b350417b6e6ab3160554967bc151f

    Affected versions

    v5.0.1
    v5.0.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2024-27094 | CVE-DB