The vulnerabilities posed denial-of-service and validator resource risks but were patched before Polygon publicly disclosed them.