mediumLogic errorEVM-Solidity
ZeroLend One: `CuratedVaultSetters::_supplyPool()` does not consider the pool cap of the underlying pool, which may cause `deposit()` to revert or lead to an unintended reordering of `supplyQueue`
- Payout
- $0
- Protocol
- ZeroLend One
- Disclosed
- Sep 10, 2024
- Source
- sherlock
ZeroLend One's CuratedVault distributes user deposits across configured underlying lending pools via `_supplyPool()`, which only respects the vault's own per-pool cap and never checks each underlying pool's internal supply cap. When an underlying pool is near …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.