The Graph's vulnerability exposure centers on its smart contract protocol implementation, a specialized and narrowly scoped product surface that operates within distributed ledger and decentralized application infrastructure. The observed weakness classes—improper access control and incorrect calculation—reflect the logic and permissioning demands of blockchain protocol code, where flaws in state management and authorization can propagate across dependent applications; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thegraph over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28410HIGH The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the token vesting contracts allows us | Mar 5, 2026 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thegraph.
Media articles that mention a CVE ID that affects a product developed by Thegraph — matched by CVE ID, not by vendor name.