<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:08:07 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-32645 — vyper performs incorrect topic logging in raw_log</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-32645</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vyperlang vyper&lt;/p&gt;
&lt;p&gt;Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect values can be logged when `raw_log` builtin is called with memory or storage arguments to be used as topics. A contract search was performed and no vulnerable contracts were found in production. The `build_IR` function of the `RawLog` class fails to properly unwrap the variables provided as topics. Consequently, incorrect values are logged as topics. As of time of publication, no fixed version is available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vyperlang vyper&lt;/p&gt;
&lt;p&gt;Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect values can be logged when `raw_log` builtin is called with memory or storage arguments to be used as topics. A contract search was performed and no vulnerable contracts were found in production. The `build_IR` function of the `RawLog` class fails to properly unwrap the variables provided as topics. Consequently, incorrect values are logged as topics. As of time of publication, no fixed version is available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-32645</guid>
    </item>
    <item>
      <title>GHSA-xchq-w5r3-4wg3 — vyper performs incorrect topic logging in raw_log</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xchq-w5r3-4wg3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;### Summary
Incorrect values can be logged when `raw_log` builtin is called with memory or storage arguments to be used as topics.&lt;/p&gt;
&lt;p&gt;A contract search was performed and no vulnerable contracts were found in production. In particular, no uses of `raw_log()` were found at all in production; it is apparently not a well-known function.&lt;/p&gt;
&lt;p&gt;### Details
The `build_IR` function of the `RawLog` class fails to properly unwrap the variables provided as topics. Consequently, incorrect values are logged as topics.&lt;/p&gt;
&lt;p&gt;### PoC
```vyper
x: bytes32&lt;/p&gt;
&lt;p&gt;@external
def f():
    self.x = 0x1234567890123456789012345678901234567890123456789012345678901234
    raw_log([self.x], b&amp;#34;&amp;#34;) # LOG1(offset:0x60, size:0x00, topic1:0x00)&lt;/p&gt;
&lt;p&gt;y: bytes32 = 0x1234567890123456789012345678901234567890123456789012345678901234
    raw_log([y], b&amp;#34;&amp;#34;) # LOG1(offset:0x80, size:0x00, topic1:0x40)
```
### Patches
Fixed in https://github.com/vyperlang/vyper/pull/3977.&lt;/p&gt;
&lt;p&gt;### Impact
Incorrect values can be logged which may result in unexpected behavior in client-side applications relying on these logs.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;### Summary
Incorrect values can be logged when `raw_log` builtin is called with memory or storage arguments to be used as topics.&lt;/p&gt;
&lt;p&gt;A contract search was performed and no vulnerable contracts were found in production. In particular, no uses of `raw_log()` were found at all in production; it is apparently not a well-known function.&lt;/p&gt;
&lt;p&gt;### Details
The `build_IR` function of the `RawLog` class fails to properly unwrap the variables provided as topics. Consequently, incorrect values are logged as topics.&lt;/p&gt;
&lt;p&gt;### PoC
```vyper
x: bytes32&lt;/p&gt;
&lt;p&gt;@external
def f():
    self.x = 0x1234567890123456789012345678901234567890123456789012345678901234
    raw_log([self.x], b&amp;#34;&amp;#34;) # LOG1(offset:0x60, size:0x00, topic1:0x00)&lt;/p&gt;
&lt;p&gt;y: bytes32 = 0x1234567890123456789012345678901234567890123456789012345678901234
    raw_log([y], b&amp;#34;&amp;#34;) # LOG1(offset:0x80, size:0x00, topic1:0x40)
```
### Patches
Fixed in https://github.com/vyperlang/vyper/pull/3977.&lt;/p&gt;
&lt;p&gt;### Impact
Incorrect values can be logged which may result in unexpected behavior in client-side applications relying on these logs.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xchq-w5r3-4wg3</guid>
    </item>
  </channel>
</rss>
