CVEs we hold for Vyperlang
Records whose assigning authority named Vyperlang as the affected vendor. Newest identifiers first, capped at 200.
CVE-2025-47774Vyper's `slice()` may elide side-effects when output length is 0vyperlang vyper CVE-2025-47285Vyper's `concat()` builtin may elide side-effects for zero-length argumentsvyperlang vyper CVE-2025-27105AugAssign evaluation order causing OOB write within the object in Vypervyperlang vyper CVE-2025-26622sqrt doesn't define rounding behavior in Vypervyperlang vyper CVE-2025-21607Success of Certain Precompile Calls not Checked in Vypervyperlang vyper CVE-2024-32649vyper performs double eval of the argument of sqrtvyperlang vyper CVE-2024-32648vyper default functions don't respect nonreentrancy keysvyperlang vyper CVE-2024-32647vyper performs double eval of raw_args in create_from_blueprintvyperlang vyper CVE-2024-32646vyper performs double eval of the slice args when buffer from adhoc locationsvyperlang vyper CVE-2024-32645vyper performs incorrect topic logging in raw_logvyperlang vyper CVE-2024-32481vyper's range(start, start + N) reverts for negative numbersvyperlang vyper CVE-2024-24567raw_call `value=` kwargs not disabled for static and delegate callsvyperlang vyper CVE-2024-24561Vyper bounds check on built-in `slice()` function can be overflowedvyperlang vyper CVE-2024-24560Vyper external calls can overflow return data to return input buffervyperlang vyper CVE-2024-22419concat built-in can corrupt memory in vypervyperlang vyper CVE-2023-46247Vyper has incorrect storage layout for contracts containing large arraysvyperlang vyper CVE-2023-42460_abi_decode input not validated in complex expressions in Vypervyperlang vyper CVE-2023-42443Vyper vulnerable to memory corruption in certain builtins utilizing `msize`vyperlang vyper CVE-2023-42441Vyper has incorrect re-entrancy lock when key is empty stringvyperlang vyper CVE-2023-41052Vyper: incorrect order of evaluation of side effects for some builtinsvyperlang vyper CVE-2023-40015Vyper: reversed order of side effects for some operationsvyperlang vyper CVE-2023-39363Vyper incorrectly allocated named re-entrancy locksvyperlang vyper CVE-2023-37902Vyper's ecrecover can return undefined data if signature does not verifyvyperlang vyper CVE-2023-32675Nonpayable default functions are sometimes payable in vypervyperlang vyper CVE-2023-32059Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal callsvyperlang vyper CVE-2023-32058Vyper vulnerable to integer overflow in loopvyperlang vyper CVE-2023-31146Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignmentvyperlang vyper CVE-2023-30629Vyper's raw_call with outsize=0 and revert_on_failure=False returns incorrect success valuevyperlang vyper CVE-2022-29255Multiple evaluation of contract address in call in vypervyperlang vyper CVE-2021-41122Bounds check missing for decimal args in Vypervyperlang vyper 40 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.