<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:14:35.833344+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-197932</id>
    <title>EUVD-2026-197932</title>
    <updated>2026-10-02T16:14:35.909737+00:00</updated>
    <content>EUVD-2026-197932</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-197932"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-24564</id>
    <title>fkie_cve-2024-24564</title>
    <updated>2026-10-02T16:14:35.909774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, start)`, if the `start` index provided has for side effect to update `b`, the byte array to extract `32` bytes from, it could be that some dirty memory is read and returned by `extract32`. This vulnerability is fixed in 0.4.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-24564"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4hwq-4cpm-8vmx</id>
    <title>GHSA-4hwq-4cpm-8vmx — Vyper's `extract32` can ready dirty memory</title>
    <updated>2026-10-02T16:14:35.909808+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vyper</p>
<p>### Summary</p>
<p>When using the built-in `extract32(b, start)`, if the `start` index provided has for side effect to update `b`, the byte array to extract `32` bytes from, it could be that some dirty memory is read and returned by `extract32`.</p>
<p>As of v0.4.0 (specifically, commit https://github.com/vyperlang/vyper/commit/3d9c537142fb99b2672f21e2057f5f202cde194f), the compiler will panic instead of generating bytecode.</p>
<p>### Details</p>
<p>Before evaluating `start`, the function `Extract32.build_IR` caches only:</p>
<p>- The pointer in memory/storage to `b`: https://github.com/vyperlang/vyper/blob/10564dcc37756f3d3684b7a91fd8f4325a38c4d8/vyper/builtins/functions.py#L916-L918
- The length of `b`: https://github.com/vyperlang/vyper/blob/10564dcc37756f3d3684b7a91fd8f4325a38c4d8/vyper/builtins/functions.py#L920-L922</p>
<p>but do not cache the actual content of `b`. This means that if the evaluation of `start` changes `b`'s content and length, an outdated length will be used with the new content when extracting 32 bytes from `b`.</p>
<p>### PoC</p>
<p>Calling the function `foo` of the following contract returns `b'uuuuuuuuuuuuuuuuuuuuuuuuuuu\x00\x00789'` meaning that `extract32` accessed some dirty memory.</p>
<p>```Vyper
var:Bytes[96]</p>
<p>@internal
def bar() -&gt; uint256:
    self.var = b'uuuuuuuuuuuuuuuuuuuuuuuuuuuuuu'
    self.var = b''
    return 3</p>
<p>@external
def foo() -&gt; bytes32:
    self.var = b'abcdefghijklmnopqrstuvwxyz123456789'
    return extract32(self.var, self.bar(), output_type=bytes32)
    # returns b'uuuuuuuuu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4hwq-4cpm-8vmx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-24564</id>
    <title>gsd-2024-24564</title>
    <updated>2026-10-02T16:14:35.909857+00:00</updated>
    <content>gsd-2024-24564</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-24564"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2024-205</id>
    <title>PYSEC-2024-205</title>
    <updated>2026-10-02T16:14:35.909870+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vyper</p>
<p>Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, start)`, if the `start` index provided has for side effect to update `b`, the byte array to extract `32` bytes from, it could be that some dirty memory is read and returned by `extract32`. This vulnerability is fixed in 0.4.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2024-205"/>
  </entry>
</feed>
