<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:03:47 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-21607 — Success of Certain Precompile Calls not Checked in Vyper</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-21607</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vyperlang vyper&lt;/p&gt;
&lt;p&gt;Vyper is a Pythonic Smart Contract Language for the EVM. When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), the success flag of the call is not checked. As a consequence an attacker can provide a specific amount of gas to make these calls fail but let the overall execution continue. Then the execution result can be incorrect. Based on EVM&amp;#39;s rules, after the failed precompile the remaining code has only 1/64 of the pre-call-gas left (as 63/64 were forwarded and spent). Hence, only fairly simple executions can follow the failed precompile calls. Therefore, we found no significantly impacted real-world contracts. None the less an advisory has been made out of an abundance of caution. This issue is fixed in 0.4.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vyperlang vyper&lt;/p&gt;
&lt;p&gt;Vyper is a Pythonic Smart Contract Language for the EVM. When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), the success flag of the call is not checked. As a consequence an attacker can provide a specific amount of gas to make these calls fail but let the overall execution continue. Then the execution result can be incorrect. Based on EVM&amp;#39;s rules, after the failed precompile the remaining code has only 1/64 of the pre-call-gas left (as 63/64 were forwarded and spent). Hence, only fairly simple executions can follow the failed precompile calls. Therefore, we found no significantly impacted real-world contracts. None the less an advisory has been made out of an abundance of caution. This issue is fixed in 0.4.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-21607</guid>
    </item>
    <item>
      <title>GHSA-vgf2-gvx8-xwc3 — Vyper Does Not Check the Success of Certain Precompile Calls</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vgf2-gvx8-xwc3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), the success flag of the call is not checked. As a consequence an attacker can provide a specific amount of gas to make these calls fail but let the overall execution continue. Then the execution result can be incorrect.&lt;/p&gt;
&lt;p&gt;Based on EVM&amp;#39;s rules, after the failed precompile the remaining code has only 1/64 of the pre-call-gas left (as 63/64 were forwarded and spent). Hence, only fairly simple executions can follow the failed precompile calls. Therefore, we found no significantly impacted real-world contracts.&lt;/p&gt;
&lt;p&gt;The fix is tracked in https://github.com/vyperlang/vyper/pull/4451.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;#### The relevant precompiles&lt;/p&gt;
&lt;p&gt;##### EcRecover&lt;/p&gt;
&lt;p&gt;EcRecover is used in vyper&amp;#39;s `ecrecover` built-in. As the precompile consumes 3000 gas, any execution after an out-of-gas EcRecover call has at most 47 gas left.&lt;/p&gt;
&lt;p&gt;##### Identity&lt;/p&gt;
&lt;p&gt;- The Identity precompile is used in vyper to perform memory copy operations. As its cost is variable, a variable amount of gas might be left after a failed call. The bigger the copy operation, the more gas can be left. Hence, a failed call to Identity could theoretically be followed by successful storage changes or emitted events.
- Identity is no longer used when `evm-version` `cancun` is used (because `MCOPY` is used instead). In 0.4.0 `cancun` is default, in 0.3.10 `cancun` is an option, otherwise `cancun` is not available. As only pre-`cancun` versions are relevant, we do…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: vyper&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), the success flag of the call is not checked. As a consequence an attacker can provide a specific amount of gas to make these calls fail but let the overall execution continue. Then the execution result can be incorrect.&lt;/p&gt;
&lt;p&gt;Based on EVM&amp;#39;s rules, after the failed precompile the remaining code has only 1/64 of the pre-call-gas left (as 63/64 were forwarded and spent). Hence, only fairly simple executions can follow the failed precompile calls. Therefore, we found no significantly impacted real-world contracts.&lt;/p&gt;
&lt;p&gt;The fix is tracked in https://github.com/vyperlang/vyper/pull/4451.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;#### The relevant precompiles&lt;/p&gt;
&lt;p&gt;##### EcRecover&lt;/p&gt;
&lt;p&gt;EcRecover is used in vyper&amp;#39;s `ecrecover` built-in. As the precompile consumes 3000 gas, any execution after an out-of-gas EcRecover call has at most 47 gas left.&lt;/p&gt;
&lt;p&gt;##### Identity&lt;/p&gt;
&lt;p&gt;- The Identity precompile is used in vyper to perform memory copy operations. As its cost is variable, a variable amount of gas might be left after a failed call. The bigger the copy operation, the more gas can be left. Hence, a failed call to Identity could theoretically be followed by successful storage changes or emitted events.
- Identity is no longer used when `evm-version` `cancun` is used (because `MCOPY` is used instead). In 0.4.0 `cancun` is default, in 0.3.10 `cancun` is an option, otherwise `cancun` is not available. As only pre-`cancun` versions are relevant, we do…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vgf2-gvx8-xwc3</guid>
    </item>
  </channel>
</rss>
