All 40 CVE vulnerabilities found in vyper, with AI-generated Chinese analysis, references, and POCs.
This page is a vulnerability aggregation resource for the Vyper smart contract compiler, categorized under general software weakness types. It compiles a comprehensive collection of security flaws and defects identified within the Vyper language and its associated tools, covering all reported incidents from its initial public releases through the present day. The data includes both critical exploits affecting deployed contracts and lower-severity bugs found in the compiler itself, ensuring a complete historical record of security postures. Users can utilize this page to track vendor advisories and development team responses regarding specific fixes, gain a deeper understanding of common weakness classes such as integer overflows or access control bypasses as they manifest in this specific environment, and investigate a product's vulnerability history to assess risk levels over time. The collection is organized to facilitate easy navigation for security researchers, developers, and auditors who need to verify the patch status of various versions or analyze trends in how certain vulnerabilities have been addressed. By providing a centralized view of these issues, the page supports informed decision-making regarding upgrade paths and security audits. It serves as a factual reference point for anyone evaluating the long-term stability and security maturity of the Vyper compiler ecosystem, helping stakeholders understand the frequency and severity of past incidents without relying on fragmented sources. This aggregated view highlights the evolution of security practices within the project and offers insights into recurring technical challenges faced during development and deployment phases.
Vendor: vyperlang
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-32058 | Vyper vulnerable to integer overflow in loop CWE-190 | 7.5 | High | 2023-05-11 |
| CVE-2023-31146 | Vyper vulnerable to OOB DynArray access when array is on both LHS and RHS of an assignment CWE-787 | 7.5 | High | 2023-05-11 |
| CVE-2023-30837 | Vyper storage allocator overflow CWE-789 | 7.5 | High | 2023-05-08 |
| CVE-2023-30629 | Vyper's raw_call with outsize=0 and revert_on_failure=False returns incorrect success value CWE-670 | 7.5 | High | 2023-04-24 |
| CVE-2022-29255 | Multiple evaluation of contract address in call in vyper CWE-670 | 8.2 | High | 2022-06-06 |
| CVE-2022-24845 | Integer bounds error in Vyper CWE-190 | 8.8 | High | 2022-04-13 |
| CVE-2022-24788 | Buffer overflow in Vyper CWE-120 | 7.1 | High | 2022-04-13 |
| CVE-2022-24787 | Incorrect Comparison in Vyper CWE-697 | 7.5 | High | 2022-04-04 |
| CVE-2021-41121 | Memory corruption in Vyper CWE-119 | 7.5 | High | 2021-10-06 |
| CVE-2021-41122 | Bounds check missing for decimal args in Vyper CWE-682 | 4.3 | Medium | 2021-10-05 |
All 40 known CVE vulnerabilities affecting vyper with full Chinese analysis, references, and POCs where available.