Uniswap's vulnerability footprint centers on decentralized exchange and routing components including its Universal Router contract and associated Web3 integration libraries for wallet connectivity. The durable signal is concentrated around concurrency and locking weaknesses that arise in smart-contract and multi-party transaction contexts, particularly race conditions and improper synchronization in shared-resource access patterns. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uniswap over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-48216HIGH Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds. | Jan 4, 2023 | 7.5 | 25 | NO | NO |
CVE-2023-30543MEDIUM @web3-react is a framework for building Ethereum Apps . In affected versions the `chainId` may be outdated if the user changes chains as part of the connection flow. This means tha | Apr 17, 2023 | 5.7 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uniswap.
Media articles that mention a CVE ID that affects a product developed by Uniswap — matched by CVE ID, not by vendor name.