Skip to content

OpenZeppelin audits Uniswap Universal Router 2.1 and V4 Periphery: one low, no criticals

October 8 differential audit covers PR #457 (cross-chain via Across) and PR #497 (per-hop slippage) — one low finding on router allowances, fixed in PR #461.

by 3 min read

OpenZeppelin published a differential audit of two Uniswap contract pull requests on October 8, 2026, on its news page. The report covers Universal Router PR #457 at commit 4be7e48 and V4 Periphery PR #497 at commit 76f8813. Two findings — one low, one note — both resolved in Uniswap PR #461. The auditors' summary line: "No significant issues were identified."

Scope

The audit is differential: it reviews only the diffs that each PR adds, against a prior audited baseline. For a mature protocol with Universal Router already in production and V4 Periphery live since the Dencun-era rollouts, this is the correct review posture.

Universal Router PR #457. Introduces cross-chain bridging via the Across protocol through a new ChainedActions.sol command and a RouteSigner.sol component that verifies signed command batches. Signed commands let a user authorize a route off-chain and have anyone execute it on-chain — the batched-swap-then-bridge flow Uniswap wants for cross-chain intents.

V4 Periphery PR #497. Scope limited to V4Router.sol and the IV4Router.sol interface. Adds optional per-hop slippage checks on multi-hop swaps. The existing V4 design enforced slippage only at the final output; the new path lets callers reject a trade mid-hop if the intermediate price moves past a per-leg bound.

Findings

Low — Router allowances through the Across deposit

The Across bridge deposit call in ChainedActions could grant token allowances to an arbitrary address passed in as the SpokePool argument. In the worst case, a crafted command would authorize an attacker-controlled contract to pull tokens the router holds.

Fix. PR #461 makes the SpokePool address immutable, baked into the router at deploy time. The arbitrary-address surface closes.

The failure mode is the kind of composable-router mistake that recurs across DEX aggregator postmortems: an "address of the bridge" parameter that was never meant to be user-controllable but is reachable through the public command interface. Making it immutable is the right fix for a router that is itself a shared execution surface across the ecosystem.

Note — Mapping readability in RouteSigner

A mapping declaration in RouteSigner.sol lacked named parameters. No security impact; readability only. Fixed alongside the low in PR #461.

What this review doesn't tell you

Differential audits only cover the diff. The audit does not re-review:

  • The Universal Router permit-and-swap primitives.
  • The V2/V3/V4 adapter logic the router dispatches into.
  • The Across protocol itself — the audit assumes SpokePool behaves per its own spec.
  • Economic / MEV-level issues on signed route batching.

Signed command verification sits in RouteSigner; a reader interested in whether a well-formed signature can authorize an unintended execution path should check that component against the full command set, not just the diff.

Context

OpenZeppelin's publication cadence on Uniswap has become something of a rolling snapshot of the router's expansion surface. The prior pass was the Universal Router SwapProxy and Periphery Audit also on OpenZeppelin's site. The pattern across the two: cross-chain and signed-command additions keep introducing new parameter surfaces, each small, each cleaned up with a tight fix PR. One low over two PRs is a healthy ratio for a router being extended into cross-chain intents, and the response time between finding and fix (one PR for both items) matches the Universal Router team's shipping cadence.

The broader context — this is the second audit this week we've covered that lands close to zero criticals on a MiCA- or production-tier contract set. See CACEIS EURXT's OpenZeppelin review from last week for the pattern on the stablecoin side.

What to read

  • The audit report on OpenZeppelin's news page above.
  • PR #457 on Uniswap/universal-router for the chained-actions and route-signer commit.
  • PR #497 on Uniswap/v4-periphery for the per-hop slippage commit.
  • PR #461 for the fix commit against both findings.

Related stories