Soliditylang maintains Solidity, the primary smart-contract programming language for the Ethereum blockchain and other distributed ledger platforms, where disclosed vulnerabilities center on the compiler and language runtime rather than a broad product suite. The observed weakness classes—out-of-bounds writes and reachable assertions—reflect the low-level code-generation and memory-safety challenges inherent to a compiler that targets bytecode execution in a decentralized environment. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Soliditylang over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36402HIGH Solidity 0.7.5 has a stack-use-after-return issue in smtutil::CHCSmtLib2Interface::querySolver. NOTE: c39a5e2b7a3fabbf687f53a2823fc087be6c1a7e is cited in the OSV "fixed" field but | Jul 1, 2021 | 7.8 | 24 | NO | NO |
CVE-2022-33069MEDIUM Ethereum Solidity v0.8.14 contains an assertion failure via SMTEncoder::indexOrMemberAssignment() at SMTEncoder.cpp. | Jun 23, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Soliditylang.
Media articles that mention a CVE ID that affects a product developed by Soliditylang — matched by CVE ID, not by vendor name.