VendorsVyperlangvyperany version
Vulnerabilities

Vyperlang Vyper any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2024-24563
Vyper array negative index vulnerability
Published 2024-02-07 · Modified
9.8EPSS 0.015
CVE-2022-24845
Integer bounds error in Vyper
Published 2022-04-13 · Modified
9.8EPSS 0.014
CVE-2022-24788
Buffer overflow in Vyper
Published 2022-04-13 · Modified
9.8EPSS 0.010
CVE-2024-24561
Vyper bounds check on built-in `slice()` function can be overflowed
Published 2024-02-01 · Modified
9.8EPSS 0.009
CVE-2024-22419
concat built-in can corrupt memory in vyper
Published 2024-01-18 · Modified
9.8EPSS 0.008
CVE-2023-31146
Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment
Published 2023-05-11 · Modified
9.1EPSS 0.012
CVE-2025-27105
AugAssign evaluation order causing OOB write within the object in Vyper
Published 2025-02-21 · Analyzed
9.1EPSS 0.006
CVE-2021-41121
Memory corruption in Vyper
Published 2021-10-06 · Modified
8.8EPSS 0.011
CVE-2022-29255
Multiple evaluation of contract address in call in vyper
Published 2022-06-06 · Modified
8.2EPSS 0.013
CVE-2023-42443
Vyper vulnerable to memory corruption in certain builtins utilizing `msize`
Published 2023-09-18 · Modified
8.1EPSS 0.008
CVE-2022-24787
Incorrect Comparison in Vyper
Published 2022-04-04 · Modified
7.5EPSS 0.010
CVE-2023-32058
Vyper vulnerable to integer overflow in loop
Published 2023-05-11 · Modified
7.5EPSS 0.009
CVE-2023-30629
Vyper's raw_call with outsize=0 and revert_on_failure=False returns incorrect success value
Published 2023-04-24 · Modified
7.5EPSS 0.009
CVE-2023-32059
Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls
Published 2023-05-11 · Modified
7.5EPSS 0.007
CVE-2023-46247
Vyper has incorrect storage layout for contracts containing large arrays
Published 2023-12-13 · Modified
7.5EPSS 0.007
CVE-2023-30837
Vyper storage allocator overflow
Published 2023-05-08 · Modified
7.5EPSS 0.007
CVE-2025-21607
Success of Certain Precompile Calls not Checked in Vyper
Published 2025-01-14 · Modified
7.5EPSS 0.007
CVE-2023-42460
_abi_decode input not validated in complex expressions in Vyper
Published 2023-09-26 · Modified
7.5EPSS 0.006
CVE-2025-27104
double eval in For List Iter in Vyper
Published 2025-02-21 · Analyzed
7.5EPSS 0.004
CVE-2025-26622
sqrt doesn't define rounding behavior in Vyper
Published 2025-02-21 · Analyzed
7.5EPSS 0.003
CVE-2024-32481
vyper's range(start, start + N) reverts for negative numbers
Published 2024-04-25 · Analyzed
5.3EPSS 0.008
CVE-2023-37902
Vyper's ecrecover can return undefined data if signature does not verify
Published 2023-07-25 · Modified
5.3EPSS 0.006
CVE-2024-24564
Vyper extract32 can ready dirty memory
Published 2024-02-26 · Analyzed
5.3EPSS 0.006
CVE-2023-32675
Nonpayable default functions are sometimes payable in vyper
Published 2023-05-19 · Modified
5.3EPSS 0.006
CVE-2024-26149
Vyper _abi_decode Memory Overflow
Published 2024-02-26 · Analyzed
5.3EPSS 0.005
CVE-2023-41052
Vyper: incorrect order of evaluation of side effects for some builtins
Published 2023-09-04 · Modified
5.3EPSS 0.005
CVE-2024-24560
Vyper external calls can overflow return data to return input buffer
Published 2024-02-02 · Modified
5.3EPSS 0.005
CVE-2023-42441
Vyper has incorrect re-entrancy lock when key is empty string
Published 2023-09-18 · Modified
5.3EPSS 0.005
CVE-2023-40015
Vyper: reversed order of side effects for some operations
Published 2023-09-04 · Modified
5.3EPSS 0.005
CVE-2024-24567
raw_call `value=` kwargs not disabled for static and delegate calls
Published 2024-01-30 · Modified
5.3EPSS 0.005
CVE-2024-32645
vyper performs incorrect topic logging in raw_log
Published 2024-04-25 · Analyzed
5.3EPSS 0.005
CVE-2024-32646
vyper performs double eval of the slice args when buffer from adhoc locations
Published 2024-04-25 · Analyzed
5.3EPSS 0.005
CVE-2024-32647
vyper performs double eval of raw_args in create_from_blueprint
Published 2024-04-25 · Analyzed
5.3EPSS 0.005
CVE-2024-32649
vyper performs double eval of the argument of sqrt
Published 2024-04-25 · Analyzed
5.3EPSS 0.005
CVE-2024-32648
vyper default functions don't respect nonreentrancy keys
Published 2024-04-25 · Analyzed
5.3EPSS 0.004
CVE-2024-24559
Vyper SHA3 code generation bug
Published 2024-02-05 · Modified
5.3EPSS 0.003
CVE-2021-41122
Bounds check missing for decimal args in Vyper
Published 2021-10-05 · Modified
4.3EPSS 0.008