id: PYSEC-2024-164 modified: 2025-01-16T21:21:41.436934Z published: 2024-02-26T20:19:05Z aliases: - CVE-2024-26149 - GHSA-9p8r-4xp4-gw5w details: Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an excessively large value is specified as the starting index for an array in `_abi_decode`, it can cause the read position to overflow. This results in the decoding of values outside the intended array bounds, potentially leading to exploitations in contracts that use arrays within `_abi_decode`. This vulnerability affects 0.3.10 and earlier versions. affected: - package: ecosystem: PyPI name: vyper purl: pkg:pypi/vyper ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 0.4.0b1 versions: - 0.1.0b1 - 0.1.0b10 - 0.1.0b11 - 0.1.0b12 - 0.1.0b13 - 0.1.0b14 - 0.1.0b15 - 0.1.0b16 - 0.1.0b17 - 0.1.0b2 - 0.1.0b3 - 0.1.0b4 - 0.1.0b5 - 0.1.0b6 - 0.1.0b7 - 0.1.0b8 - 0.1.0b9 - 0.2.1 - 0.2.10 - 0.2.11 - 0.2.12 - 0.2.13 - 0.2.14 - 0.2.15 - 0.2.16 - 0.2.2 - 0.2.3 - 0.2.4 - 0.2.5 - 0.2.6 - 0.2.7 - 0.2.8 - 0.2.9 - 0.3.0 - 0.3.1 - 0.3.10 - 0.3.10rc1 - 0.3.10rc2 - 0.3.10rc3 - 0.3.10rc4 - 0.3.10rc5 - 0.3.2 - 0.3.3 - 0.3.4 - 0.3.5 - 0.3.6 - 0.3.7 - 0.3.8 - 0.3.9 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N references: - type: ADVISORY url: https://github.com/vyperlang/vyper/security/advisories/GHSA-9p8r-4xp4-gw5w - type: EVIDENCE url: https://github.com/vyperlang/vyper/security/advisories/GHSA-9p8r-4xp4-gw5w - type: FIX url: https://github.com/vyperlang/vyper/security/advisories/GHSA-9p8r-4xp4-gw5w - type: ADVISORY url: https://github.com/advisories/GHSA-9p8r-4xp4-gw5w