There is lack of access control in the newEscrow contract.
Anyone can create an escrow contract without authorization.
Since the contract is publicly accessible without access control, malicious users could deploy a large number of escrow contracts in a short period, potentially leading to a Denial-of-Service (DoS) attack.
Manual review
Implement some form of access control on who can create an escrow contract.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.