<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 18:49:23 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-187355</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-187355</link>
      <description>EUVD-2026-187355</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-187355</guid>
    </item>
    <item>
      <title>fkie_cve-2023-42460</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-42460</link>
      <description>&lt;p&gt;Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is nested in an expression. Uses of `_abi_decode()` can be constructed which allow for bounds checking to be bypassed resulting in incorrect results. This issue has not yet been fixed, but a fix is expected in release `0.3.10`. Users are advised to reference pull request #3626.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is nested in an expression. Uses of `_abi_decode()` can be constructed which allow for bounds checking to be bypassed resulting in incorrect results. This issue has not yet been fixed, but a fix is expected in release `0.3.10`. Users are advised to reference pull request #3626.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-42460</guid>
    </item>
    <item>
      <title>GHSA-cx2q-hfxr-rj97 — Vyper's `_abi_decode` input not validated in complex expressions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cx2q-hfxr-rj97</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;### Impact
`_abi_decode()` does not validate input when it is nested in an expression. the following example gets correctly validated (bounds checked):
```vyper
x: int128 = _abi_decode(slice(msg.data, 4, 32), int128)
```&lt;/p&gt;
&lt;p&gt;however, the following example is not bounds checked
```vyper
@external
def abi_decode(x: uint256) -&amp;gt; uint256:
    a: uint256 = convert(_abi_decode(slice(msg.data, 4, 32), (uint8)), uint256) + 1
    return a  # abi_decode(256) returns: 257
```&lt;/p&gt;
&lt;p&gt;the issue can be triggered by constructing an example where the output of `_abi_decode` is not internally passed to `make_setter` (an internal codegen routine) or other input validating routine.&lt;/p&gt;
&lt;p&gt;### Patches
https://github.com/vyperlang/vyper/pull/3626&lt;/p&gt;
&lt;p&gt;### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;### References
_Are there any links users can visit to find out more?_&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;### Impact
`_abi_decode()` does not validate input when it is nested in an expression. the following example gets correctly validated (bounds checked):
```vyper
x: int128 = _abi_decode(slice(msg.data, 4, 32), int128)
```&lt;/p&gt;
&lt;p&gt;however, the following example is not bounds checked
```vyper
@external
def abi_decode(x: uint256) -&amp;gt; uint256:
    a: uint256 = convert(_abi_decode(slice(msg.data, 4, 32), (uint8)), uint256) + 1
    return a  # abi_decode(256) returns: 257
```&lt;/p&gt;
&lt;p&gt;the issue can be triggered by constructing an example where the output of `_abi_decode` is not internally passed to `make_setter` (an internal codegen routine) or other input validating routine.&lt;/p&gt;
&lt;p&gt;### Patches
https://github.com/vyperlang/vyper/pull/3626&lt;/p&gt;
&lt;p&gt;### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_&lt;/p&gt;
&lt;p&gt;### References
_Are there any links users can visit to find out more?_&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cx2q-hfxr-rj97</guid>
    </item>
    <item>
      <title>gsd-2023-42460</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-42460</link>
      <description>gsd-2023-42460</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-42460</guid>
    </item>
    <item>
      <title>PYSEC-2023-191</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2023-191</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is nested in an expression. Uses of `_abi_decode()` can be constructed which allow for bounds checking to be bypassed resulting in incorrect results. This issue has not yet been fixed, but a fix is expected in release `0.3.10`. Users are advised to reference pull request #3626.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is nested in an expression. Uses of `_abi_decode()` can be constructed which allow for bounds checking to be bypassed resulting in incorrect results. This issue has not yet been fixed, but a fix is expected in release `0.3.10`. Users are advised to reference pull request #3626.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2023-191</guid>
    </item>
  </channel>
</rss>
