CVE-2026-57445: 1hive Gardens-v2

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In dfba919e218e20d52db9f7b2e8d292d45a46c91b and prior, normal beneficiary payout paths in StreamingEscrow preserve depositAmount() while an active stream needs an escrow reserve. However, the approve-side dispute resolution path drains the whole available escrow balance to the proposal beneficiary. At time of publication, there are no publicly known patches.

Affected products

  • 1hive Gardens-v2: up to and including dfba919e218e20d52db9f7b2e8d292d45a46c91b

Published 2026-09-03. Last modified 2026-09-09.