<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T16:00:40.129335+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-9774</id>
    <title>EUVD-2026-9774</title>
    <updated>2026-10-05T16:00:40.132561+00:00</updated>
    <content>EUVD-2026-9774</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-9774"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-46247</id>
    <title>fkie_cve-2023-46247</title>
    <updated>2026-10-05T16:00:40.132601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Contracts containing large arrays might underallocate the number of slots they need by 1. Prior to v0.3.8, the calculation to determine how many slots a storage variable needed used `math.ceil(type_.size_in_bytes / 32)`. The intermediate floating point step can produce a rounding error if there are enough bits set in the IEEE-754 mantissa. Roughly speaking, if `type_.size_in_bytes` is large (&gt; 2**46), and slightly less than a power of 2, the calculation can overestimate how many slots are needed by 1. If `type_.size_in_bytes` is slightly more than a power of 2, the calculation can underestimate how many slots are needed by 1. This issue is patched in version 0.3.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-46247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6m97-7527-mh74</id>
    <title>GHSA-6m97-7527-mh74 — incorrect storage layout for contracts containing large arrays</title>
    <updated>2026-10-05T16:00:40.132639+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vyper</p>
<p>### Impact
contracts containing large arrays might underallocate the number of slots they need. prior to v0.3.8, the calculation to determine how many slots a storage variable needed used `math.ceil(type_.size_in_bytes / 32)`:</p>
<p>https://github.com/vyperlang/vyper/blob/6020b8bbf66b062d299d87bc7e4eddc4c9d1c157/vyper/semantics/validation/data_positions.py#L197</p>
<p>the intermediate floating point step can produce a rounding error if there are enough bits set in the IEEE-754 mantissa. roughly speaking, if `type_.size_in_bytes` is large (&gt; 2**46), and slightly less than a power of 2, the calculation can overestimate how many slots are needed. if `type_.size_in_bytes` is slightly more than a power of 2, the calculation can underestimate how many slots are needed.</p>
<p>the following two example contracts can result in overwriting of the variable `vulnerable`:
```vyper
large_array: address[2**64 + 1]  # type_.size_in_bytes == 32 * (2**64 + 1); math.ceil(type_.size_in_bytes / 32) &lt; 2**64 + 1
vulnerable: uint256</p>
<p># writing to self.large_array[2**64] will overwrite self.vulnerable
```
```vyper
large_dynarray: DynArray[address, 2**64]  # Dynarray has a length word in front, its size in bytes is 32 * (2**64 + 1)
vulnerable: uint256</p>
<p># writing to self.large_dynarray[2**64 - 1] will overwrite self.vulnerable
```</p>
<p>note that in the latter case, the risk of `vulnerable` being overwritten is relatively small, since it would cost roughly $1.45 million trillion USD at today's gas prices (gas price 20gwei…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6m97-7527-mh74"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-46247</id>
    <title>gsd-2023-46247</title>
    <updated>2026-10-05T16:00:40.132686+00:00</updated>
    <content>gsd-2023-46247</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-46247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2023-307</id>
    <title>PYSEC-2023-307</title>
    <updated>2026-10-05T16:00:40.132700+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vyper</p>
<p>Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Contracts containing large arrays might underallocate the number of slots they need by 1. Prior to v0.3.8, the calculation to determine how many slots a storage variable needed used `math.ceil(type_.size_in_bytes / 32)`. The intermediate floating point step can produce a rounding error if there are enough bits set in the IEEE-754 mantissa. Roughly speaking, if `type_.size_in_bytes` is large (&gt; 2**46), and slightly less than a power of 2, the calculation can overestimate how many slots are needed by 1. If `type_.size_in_bytes` is slightly more than a power of 2, the calculation can underestimate how many slots are needed by 1. This issue is patched in version 0.3.8.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2023-307"/>
  </entry>
</feed>
