All reports
mediumLogic errorEVM-Solidity

ZeroLend One: `CuratedVaultSetters::_supplyPool()` does not consider the pool cap of the underlying pool, which may cause `deposit()` to revert or lead to an unintended reordering of `supplyQueue`

Payout
$0
Protocol
ZeroLend One
Disclosed
Sep 10, 2024
Source
sherlock

ZeroLend One's CuratedVault distributes user deposits across configured underlying lending pools via `_supplyPool()`, which only respects the vault's own per-pool cap and never checks each underlying pool's internal supply cap. When an underlying pool is near …

Similar reports

  • No close matches yet.

References

This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.