Loading HuntDB...

GHSA-4mrx-6fxm-8jpg

GitHub Security Advisory

Buffer Overflow in vyper

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

### Impact
Importing a function from a JSON interface which returns `bytes` generates bytecode which does not clamp bytes length, potentially resulting in a buffer overrun.

### Patches
0.3.2 (as of https://github.com/vyperlang/vyper/commit/049dbdc647b2ce838fae7c188e6bb09cf16e470b)

### Workarounds
Use .vy interfaces.

Affected Packages

PyPI vyper
Affected versions: 0 (fixed in 0.3.2)

Related CVEs

Key Information

GHSA ID
GHSA-4mrx-6fxm-8jpg
Published
April 20, 2022 8:31 PM
Last Modified
November 19, 2024 4:04 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
vyper
GitHub Reviewed
✓ Yes

Dataset

Last updated: November 26, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.