CVE-2026-57445
Last modified
CVE-2026-57445 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In dfba919e218e20d52db9f7b2e8d292d45a46c91b and prior, normal beneficiary payout paths in StreamingEscrow preserve depositAmount() while an active stream needs an escrow reserve. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In dfba919e218e20d52db9f7b2e8d292d45a46c91b and prior, normal beneficiary payout paths in StreamingEscrow preserve depositAmount() while an active stream needs an escrow reserve. However, the approve-side dispute resolution path drains the whole available escrow balance to the proposal beneficiary. At time of publication, there are no publicly known patches.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| 1Hive | gardens-v2 | <= dfba919e218e20d52db9f7b2e8d292d45a46c91b |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-57445?
How severe is CVE-2026-57445?
How do I fix CVE-2026-57445?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-57438Nokogiri is an open source XML and HTML library for the Ruby…6.6
- CVE-2026-57439CyberChef is a web app for encryption, encoding, compression…5
- CVE-2026-57440The EmbedVideo Extension is a MediaWiki extension which adds…7.5
- CVE-2026-57441MCPVault is a lightweight Model Context Protocol server for …8.4
- CVE-2026-57442MCPVault is a lightweight Model Context Protocol server for …6.9
- CVE-2026-57443SCBE-AETHERMOORE is a geometric AI governance and evaluation…7.5
- CVE-2026-57449Actual is a local-first personal finance tool. Prior to 26.7…7.1
- CVE-2026-5745A flaw was found in libarchive. A NULL pointer dereference v…5.5
- CVE-2026-57451Vim is an open source, command line text editor. Prior to 9.…6.1
- CVE-2026-57452Vim is an open source, command line text editor. Prior to 9.…5.5
- CVE-2026-57453Vim is an open source, command line text editor. From 9.1.17…7.3
- CVE-2026-57454Vim is an open source, command line text editor. From 9.2.03…6.1
Are you affected by CVE-2026-57445?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
