Source status: V12's public report documents the autonomous workflow, NEAR's acknowledgment, and mitigation. No CVE was public at indexing time.
Summary
The issue allowed state to evade the intended garbage-collection path, creating a route to persistent storage growth and service degradation. NEAR acknowledged the report and applied mitigation.
This accepted, public, no-CVE issue is counted as one finding rather than as a speculative protocol weakness.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.