The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the token vesting contracts allows users to access tokens that should still be locked according to their vesting schedule. This issue has been patched in version 3.0.0.
History

Thu, 05 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
Description The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the token vesting contracts allows users to access tokens that should still be locked according to their vesting schedule. This issue has been patched in version 3.0.0.
Title The Graph: Revocable vesting contracts allows early access to locked tokens
Weaknesses CWE-284
CWE-682
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-05T20:11:54.254Z

Reserved: 2026-02-27T15:33:57.289Z

Link: CVE-2026-28410

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-05T21:16:21.873

Modified: 2026-03-05T21:16:21.873

Link: CVE-2026-28410

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.