目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-55658— Gardens v2 StreamingEscrow 资金损失漏洞

一分钟漏洞结论

影响对象
1Hive gardens-v2
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Gardens v2 是一个模块化治理框架,使社区能够创建和管理具有可定制参数和投票机制的多个治理池。在版本 3e595f3 及更早版本中,当流式提案获得资金时,流式合约集群会将真实的资金池资金转入该提案的 StreamingEscrow(流式托管),用于支撑超级流式常流协议(包括 CFA 存款以及 0.5% 的保证金)。 函数会将托管合约中的 GDA 成员份额清零,但从未追回已停放的余额;而无需授权的 函数会将托管合约的整个余额(包括资金池的资金缓冲)转给受益人。该受益人由提案提交者选定,默认即为提交者本身。唯一

CVSS 7.7 · High

可能的 ATT&CK 技术 2 AI

T1019 T1529 · System Shutdown/Reboot

影响版本矩阵 1

厂商产品 版本范围状态
1Hive gardens-v2 <= 3e595f3 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-55658 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Gardens v2: StreamingEscrow buffer drains to the proposal beneficiary on cancel via the permissionless claim()
来源: CVE Program / CVE List V5
Vulnerability Description
Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool funds into the proposal's StreamingEscrow to back the Superfluid constant flow agreement (the CFA deposit, plus a 0.5 percent margin). cancelProposal then zeroes the escrow's GDA member units but never reclaims that parked balance, and the permissionless claim() forwards the escrow's entire balance, including the pool funded buffer, to the beneficiary. The beneficiary is chosen by the proposal submitter and defaults to the submitter. The only path that returns escrow funds to the pool is drainToStrategy, which is onlyStrategy and is reached solely from the dispute reject ruling, never from cancel or natural completion. At time of publication, there are no publicly known patches.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
1Hive gardens-v2 <= 3e595f3 -

二、漏洞 CVE-2026-55658 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-55658 的情报信息

登录查看更多情报信息。

CVE-2026-55658 厂商安全公告 (1)

同批安全公告 · 1Hive · 2026-09-03 · 共 3 条

CVE-2026-53924 8.7 HIGH Gardens v2 流式提案争议绕过同步溢出
CVE-2026-57445 8.7 HIGH Gardens v2 争议仲裁导致流式托管金库耗尽

IV. Related Vulnerabilities

V. Comments for CVE-2026-55658

暂无评论


发表评论