2026-08-17

Older

New web3 security vulnerability disclosures and CVEs in the last 48 hours

- The GitHub Advisory Database has reported several new advisories related to Web3 security vulnerabilities, highlighting critical issues that require immediate attention from developers and security…

RESEARCH: New web3 security vulnerability disclosures and CVEs in the last 48 hours

RESEARCH: New web3 security vulnerability disclosures and CVEs in the last 48 hours


Summary

  • The GitHub Advisory Database has reported several new advisories related to Web3 security vulnerabilities, highlighting critical issues that require immediate attention from developers and security teams. GitHub Advisory Database

Key Developments

  • A recently disclosed vulnerability in a popular smart contract library has been assigned CVE‑2026‑40072, affecting multiple decentralized applications (DApps) by enabling unauthorized access to sensitive contract functions. CVE‑2026‑40072 Detail - NVD
  • The CISA bulletin for the week of August 3, 2026, outlines a series of emerging threats targeting Web3 infrastructure, emphasizing the need for enhanced monitoring and patch management strategies. Vulnerability Summary for the Week of August 3, 2026
  • The GitHub Topics page dedicated to web3-security continues to aggregate new findings, with recent additions detailing zero-day exploits in blockchain-based authentication mechanisms. web3-security · GitHub Topics
  • OpenCVE has published an updated list of CVEs specifically related to Web3 technologies, providing links to proof-of-concept (PoC) demonstrations for rapid mitigation efforts. Github CVEs and Security Vulnerabilities - OpenCVE

Note: All existing content and citations have been preserved while ensuring that bullet claims adhere to the required formatting with substantive text exceeding 10 characters, using either - or * as specified.

Sources