CVE-2026-28410 - The Graph: Revocable vesting contracts allows early access to locked tokens

CVE-2026-28410 - The Graph: Revocable vesting contracts allows early access to locked tokens

CVE ID : CVE-2026-28410 Published : March 5, 2026, 9:16 p.m. | 27 minutes ago Description : The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the token vesting contracts allows users to access tokens that should still be locked according to their vesting schedule. This issue has been patched in version 3.0.0. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
March 5, 2026