# UUPSUpgradeable Vulnerability Post-mortem

**URL:** <https://forum.openzeppelin.com/t/uupsupgradeable-vulnerability-post-mortem/15680>\
**Category:** Announcements\
**Created:** [September 16, 2021, 5:29pm UTC](https://forum.openzeppelin.com/t/uupsupgradeable-vulnerability-post-mortem/15680 "2021-09-16T17:29:26Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![spalladino](https://sea2.discourse-cdn.com/flex022/user_avatar/forum.openzeppelin.com/spalladino/32/22_2.png) [@spalladino](https://forum.openzeppelin.com/u/spalladino)\
**Post date:** [September 23, 2021, 5:57pm UTC](https://forum.openzeppelin.com/t/uupsupgradeable-vulnerability-post-mortem/15680/4 "2021-09-23T17:57:48Z")

</div>

> [@gnarvaja](#):
>
> Perhaps you can check what I proposed in [Why not using ERC165 - IUUPSUpgradreable - #3 by gnarvaja](https://forum.openzeppelin.com/t/why-not-using-erc165-iuupsupgradreable/12807/3) as an alternative to doing the _rollback test_ . Of course, it has the problem identified by @frangio in the reply but perhaps is safer than the current rollback test.

Yes, we have been discussing this approach. The issue mentioned by Fran can be circumvented by changing the returned value in `supportsInterface` depending on whether the call is madde on the implementation or not, which can be detected via immutable vars (see the fix that was added on the latest version).

We didn't want to introduce any major changes in this fix, but we'll evaluate this for the next big release.

---

_[View the full topic](https://forum.openzeppelin.com/t/uupsupgradeable-vulnerability-post-mortem/15680)._
