{"id":"CVE-2024-27094","aliases":["GHSA-9vx6-7xxf-x967"],"url":"https://o3.security/vulnerability/CVE-2024-27094","summary":"OpenZeppelin Contracts base64 encoding may read from potentially dirty memory","details":"OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes` input by iterating over it in chunks of 3 bytes. When this input is not a multiple of 3, the last iteration may read parts of the memory that are beyond the input buffer. The vulnerability is fixed in 5.0.2 and 4.9.6.","published":"2024-02-29T18:18:24.721Z","modified":"2026-07-16T03:46:51.685697107Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@openzeppelin/contracts","fixedVersion":"4.9.6"},{"ecosystem":"npm","name":"@openzeppelin/contracts-upgradeable","fixedVersion":"5.0.2"},{"ecosystem":"npm","name":"@openzeppelin/contracts","fixedVersion":"5.0.2"},{"ecosystem":"npm","name":"@openzeppelin/contracts-upgradeable","fixedVersion":"4.9.6"}],"fix":{"url":"https://github.com/OpenZeppelin/openzeppelin-contracts-upgradeable/commit/2d081f24cac1a867f6f73d512f2022e1fa987854","label":"OpenZeppelin/openzeppelin-contracts-upgradeable@2d081f2"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27094.json"},{"type":"ADVISORY","url":"https://github.com/OpenZeppelin/openzeppelin-contracts/security/advisories/GHSA-9vx6-7xxf-x967"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-27094"},{"type":"FIX","url":"https://github.com/OpenZeppelin/openzeppelin-contracts-upgradeable/commit/2d081f24cac1a867f6f73d512f2022e1fa987854"},{"type":"FIX","url":"https://github.com/OpenZeppelin/openzeppelin-contracts-upgradeable/commit/723f8cab09cdae1aca9ec9cc1cfa040c2d4b06c1"},{"type":"FIX","url":"https://github.com/OpenZeppelin/openzeppelin-contracts/commit/92224533b1263772b0774eec3134e132a3d7b2a6"},{"type":"FIX","url":"https://github.com/OpenZeppelin/openzeppelin-contracts/commit/a6286d0fded8771b3a645e5813e51993c490399c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-16T03:46:51.685697107Z"}}