Skip to content

Fix/security issues - #664

Merged
nonsobethel0-dev merged 2 commits into
Parashield-Protocol:mainfrom
ReinaMaze:fix/security-issues
Sep 29, 2026
Merged

nonsobethel0-dev merged 2 commits into
Parashield-Protocol:mainfrom
ReinaMaze:fix/security-issues

Conversation

@ReinaMaze

Copy link
Copy Markdown
Contributor

close #464
close #465
close #466
close #467

1. GovernanceDao: Add safeguard for division by zero in adaptive quorum
   - When participation history is empty, fall back to base quorum
   - Prevents panic on first proposal creation with adaptive quorum enabled
   - Severity: Medium

2. PolicyEngine: Add oracle_key length validation in buy_policy
   - Enforce 32 character maximum on oracle_key parameter
   - Prevents excessively long keys that could cause oracle lookup issues
   - Aligns on-chain validation with backend constraints
   - Severity: Medium

3. RiskPool: Add reinsurer interface validation in set_reinsurance
   - Verify reinsurer implements IReinsurer interface via test call
   - Prevents malicious/buggy contracts from being set as reinsurer
   - Protects pool from fraudulent recovery amounts
   - Severity: High

All fixes include inline security comments explaining the issue and solution.
@drips-wave

drips-wave Bot commented Sep 27, 2026

Copy link
Copy Markdown

@ReinaMaze Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@nonsobethel0-dev
nonsobethel0-dev merged commit cf814fb into Parashield-Protocol:main Sep 29, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants