<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 14:52:17 +0000</lastBuildDate>
    <item>
      <title>CVE-2021-41122 — Bounds check missing for decimal args in Vyper</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2021-41122</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vyperlang vyper&lt;/p&gt;
&lt;p&gt;Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions external functions did not properly validate the bounds of decimal arguments. The can lead to logic errors. This issue has been resolved in version 0.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vyperlang vyper&lt;/p&gt;
&lt;p&gt;Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions external functions did not properly validate the bounds of decimal arguments. The can lead to logic errors. This issue has been resolved in version 0.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2021-41122</guid>
    </item>
    <item>
      <title>GHSA-c7pr-343r-5c46 — missing clamps for decimal args in external functions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c7pr-343r-5c46</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The following code does not properly validate that its input is in bounds.&lt;/p&gt;
&lt;p&gt;```python
@external
def foo(x: decimal) -&amp;gt; decimal:
    return x
```&lt;/p&gt;
&lt;p&gt;### Patches
0.3.0 / #2447&lt;/p&gt;
&lt;p&gt;### Workarounds
Don&amp;#39;t use decimal args&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The following code does not properly validate that its input is in bounds.&lt;/p&gt;
&lt;p&gt;```python
@external
def foo(x: decimal) -&amp;gt; decimal:
    return x
```&lt;/p&gt;
&lt;p&gt;### Patches
0.3.0 / #2447&lt;/p&gt;
&lt;p&gt;### Workarounds
Don&amp;#39;t use decimal args&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c7pr-343r-5c46</guid>
    </item>
  </channel>
</rss>
