<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:33:35.238293+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-47285</id>
    <title>CVE-2025-47285 — Vyper's `concat()` builtin may elide side-effects for zero-length arguments</title>
    <updated>2026-10-02T20:33:35.240382+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> vyperlang vyper</p>
<p>Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, `concat()` may skip evaluation of side effects when the length of an argument is zero. This is due to a fastpath in the implementation which skips evaluation of argument expressions when their length is zero. In practice, it would be very unusual in user code to construct zero-length bytestrings using an expression with side-effects, since zero-length bytestrings are typically constructed with the empty literal `b""`; the only way to construct an empty bytestring which has side effects would be with the ternary operator introduced in v0.3.8, e.g. `b"" if self.do_some_side_effect() else b""`. The fix is available in pull request 4644 and expected to be part of the 0.4.2 release. As a workaround, don't have side effects in expressions which construct zero-length bytestrings.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-47285"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qhr6-mgqr-mchm</id>
    <title>GHSA-qhr6-mgqr-mchm — Vyper's `concat()` builtin may elide side-effects for zero-length arguments</title>
    <updated>2026-10-02T20:33:35.240477+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: vyper</p>
<p>### Impact
`concat()` may skip evaluation of side effects when the length of an argument is zero. this is due to a fastpath in the implementation which skips evaluation of argument expressions when their length is zero:
https://github.com/vyperlang/vyper/blob/68b68c4b30c5ef2f312b4674676170b8a6eaa316/vyper/builtins/functions.py#L560-L562</p>
<p>in practice, it would be very unusual in user code to construct zero-length bytestrings using an expression with side-effects, since zero-length bytestrings are typically constructed with the empty literal `b""`; the only way to construct an empty bytestring which has side effects would be with the ternary operator introduced in v0.3.8, e.g. `b"" if self.do_some_side_effect() else b""`.</p>
<p>the following example demonstrates how the issue would look in user code
```vyper
counter: public(uint256)</p>
<p>@external
def test() -&gt; Bytes[256]:
    a: Bytes[256] = concat(b"" if self.sideeffect() else b"", b"aaaa")
    return a</p>
<p>def sideeffect() -&gt; bool:
    self.counter += 1
    return True
```</p>
<p>the severity assigned is low, since, as mentioned, this would be a very unusual pattern in user-code.</p>
<p>### Patches</p>
<p>fix is tracked in https://github.com/vyperlang/vyper/pull/4644</p>
<p>### Workarounds
don't have side effects in expressions which construct zero-length bytestrings.</p>
<p>### References
_Are there any links users can visit to find out more?_</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qhr6-mgqr-mchm"/>
  </entry>
</feed>
