CVE-2026-55658
Last modified
CVE-2026-55658 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool funds into the proposal's StreamingEscrow to back the Superfluid constant flow agreement (the CFA deposit, plus a 0.5 percent margin). EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool funds into the proposal's StreamingEscrow to back the Superfluid constant flow agreement (the CFA deposit, plus a 0.5 percent margin). cancelProposal then zeroes the escrow's GDA member units but never reclaims that parked balance, and the permissionless claim() forwards the escrow's entire balance, including the pool funded buffer, to the beneficiary. The beneficiary is chosen by the proposal submitter and defaults to the submitter. The only path that returns escrow funds to the pool is drainToStrategy, which is onlyStrategy and is reached solely from the dispute reject ruling, never from cancel or natural completion. At time of publication, there are no publicly known patches.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| 1Hive | gardens-v2 | <= 3e595f3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-55658?
How severe is CVE-2026-55658?
How do I fix CVE-2026-55658?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55650Outerbase Studio is a lightweight browser-based database GUI…4.4
- CVE-2026-55651Easy!Appointments is a self hosted appointment scheduler. In…7.1
- CVE-2026-55652Wekan is open source kanban built with Meteor. Prior to 9.46…9.8
- CVE-2026-55653A flaw was found in OpenSSH. A malicious SSH server can expl…6.5
- CVE-2026-55654A flaw was found in OpenSSH. This vulnerability, a heap out-…3.7
- CVE-2026-55655A flaw was found in OpenSSH. A local unprivileged attacker o…6.1
- CVE-2026-55659Grist is spreadsheet software using Python as its formula la…7.7
- CVE-2026-5566A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7…8.8
- CVE-2026-55660Tina is a headless content management system. In versions pr…7.6
- CVE-2026-55661Tina is a headless content management system. In versions pr…4.8
- CVE-2026-55663mediasoup is a WebRTC video conferencing system. From versio…5.6
- CVE-2026-55664Grist is spreadsheet software using Python as its formula la…4.3
Are you affected by CVE-2026-55658?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
