# CVE-2026-57445

## Summary

- **CVE ID:** CVE-2026-57445
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-703
- **Published:** Sep 3, 2026
- **Last Modified:** Sep 3, 2026

## Description

Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In dfba919e218e20d52db9f7b2e8d292d45a46c91b and prior, normal beneficiary payout paths in StreamingEscrow preserve depositAmount() while an active stream needs an escrow reserve. However, the approve-side dispute resolution path drains the whole available escrow balance to the proposal beneficiary. At time of publication, there are no publicly known patches.

## Affected Products

- 1Hive — gardens-v2 (<= dfba919e218e20d52db9f7b2e8d292d45a46c91b)

## References

- [CNA](https://github.com/1Hive/gardens-v2/security/advisories/GHSA-3xpr-2mm7-77j7)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.25%
- **EPSS Percentile:** 16.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._