Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-57445— Gardens v2: Approve-side dispute resolution drains active streaming escrow reserve

Quick assessment

Affected
1Hive gardens-v2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Gardens v2 是一个模块化的治理框架,使社区能够创建并管理具有可定制参数和投票机制的多个治理池。在 dfba919e218e20d52db9f7b2e8d292d45a46c91b 及其之前的版本中,StreamingEscrow 中正常的受益方支付路径会保留 depositAmount(),而活跃的流(stream)需要预留托管保证金。然而,在审批方的争议解决路径中,整个可用的托管余额会被全部划转给提案受益方。截至本描述发布时,尚无公开已知的补丁。

CVSS 8.7 · High

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 1

VendorProduct Version RangeStatus
1Hive gardens-v2 <= dfba919e218e20d52db9f7b2e8d292d45a46c91b affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-57445

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gardens v2: Approve-side dispute resolution drains active streaming escrow reserve
Source: CVE Program / CVE List V5
Vulnerability Description
Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In dfba919e218e20d52db9f7b2e8d292d45a46c91b and prior, normal beneficiary payout paths in StreamingEscrow preserve depositAmount() while an active stream needs an escrow reserve. However, the approve-side dispute resolution path drains the whole available escrow balance to the proposal beneficiary. At time of publication, there are no publicly known patches.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对异常条件检查或处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
1Hive gardens-v2 <= dfba919e218e20d52db9f7b2e8d292d45a46c91b -

II. Public POCs for CVE-2026-57445

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-57445

登录查看更多情报信息。

Vendor Advisories for CVE-2026-57445 (1)

Same Patch Batch · 1Hive · 2026-09-03 · 3 CVEs total

CVE-2026-53924 8.7 HIGH Gardens v2: Permissionless syncOutflow bypasses streaming proposal disputes
CVE-2026-55658 7.7 HIGH Gardens v2: StreamingEscrow buffer drains to the proposal beneficiary on cancel via the pe

IV. Related Vulnerabilities

V. Comments for CVE-2026-57445

No comments yet


Leave a comment