Ens.Domains operates the Ethereum Name Service, a decentralized domain-name and address-resolution system on the Ethereum blockchain, with its vulnerability footprint centered on smart-contract and cryptographic components. The observed weakness classes—improper authorization, improper verification of cryptographic signatures, and integer overflow—reflect the access-control and mathematical precision demands of blockchain-based identity and naming infrastructure. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ens.Domains over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-5232HIGH A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain ownership without the new owners consent or awareness. A new | Jan 31, 2020 | 8.7 | 28 | NO | NO |
CVE-2026-22866HIGH Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In versions 1.6.2 and prior, the `RSASHA256Algorithm` and `RSASHA | Feb 25, 2026 | 7.5 | 24 | NO | NO |
CVE-2023-38698MEDIUM Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. According to the documentation, controllers are allowed to regist | Aug 4, 2023 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ens.Domains.
Media articles that mention a CVE ID that affects a product developed by Ens.Domains — matched by CVE ID, not by vendor name.