<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:29:51.382550+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-26149</id>
    <title>CVE-2024-26149 — Vyper _abi_decode Memory Overflow</title>
    <updated>2026-10-02T20:29:51.415307+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> vyperlang vyper</p>
<p>Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an excessively large value is specified as the starting index for an array in `_abi_decode`, it can cause the read position to overflow. This results in the decoding of values outside the intended array bounds, potentially leading to exploitations in contracts that use arrays within `_abi_decode`. This vulnerability affects 0.3.10 and earlier versions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-26149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9p8r-4xp4-gw5w</id>
    <title>GHSA-9p8r-4xp4-gw5w — Vyper's `_abi_decode` vulnerable to Memory Overflow</title>
    <updated>2026-10-02T20:29:51.415377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vyper</p>
<p>## Summary</p>
<p>If an excessively large value is specified as the starting index for an array in `_abi_decode`, it can cause the read position to overflow. This results in the decoding of values outside the intended array bounds, potentially leading to bugs in contracts that use arrays within `_abi_decode`. The advisory has been assigned low severity, because it is only observable if there is a memory write between two invocations of `abi_decode` on the same input.</p>
<p>## Proof of Concept</p>
<p>```vyper
event Pwn:
    pass</p>
<p>@external
def f(x: Bytes[32 * 3]):
    a: Bytes[32] = b"foo"
    y: Bytes[32 * 3] = x</p>
<p>decoded_y1: Bytes[32] = _abi_decode(y, Bytes[32])
    a = b"bar"
    decoded_y2: Bytes[32] = _abi_decode(y, Bytes[32])</p>
<p>if decoded_y1 != decoded_y2:
        log Pwn()
```</p>
<p>Sending the following calldata results in `Pwn` being emitted.</p>
<p>```
0xd45754f8
0000000000000000000000000000000000000000000000000000000000000020
0000000000000000000000000000000000000000000000000000000000000060
ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffa0
```</p>
<p>### Patches
Patched in https://github.com/vyperlang/vyper/pull/3925, https://github.com/vyperlang/vyper/pull/4091, https://github.com/vyperlang/vyper/pull/4144, https://github.com/vyperlang/vyper/pull/4060.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9p8r-4xp4-gw5w"/>
  </entry>
</feed>
