GHSA-VG88-3V92-RJX2

Vulnerability from github – Published: 2026-10-06 15:20 – Updated: 2026-10-06 15:20
VLAI
Summary
Vyper: Return inside for loop more than 1 level deep
Details

VVE-2020-0002

Earlier today, we received a responsible disclosure of a potential issue from @michwill (developer of @curvefi) for Vyper users who use return statements inside for loops of nested internal calls. Returning inside a for loop causes an invalid jump dest, reverting the transaction unnecessarily.

MWE:

@internal
def _baz():
    for i in range(1):
        return  # Stack underflow happens here

@internal
def _bar():
    self._baz()

@external
def foo():
    self._bar()

Impact

Impact is minor, it is unlikely a user would encounter this problem unless they were working with nested calls, and return statements inside calls. Even in that scenario, you would encounter a revert which should be noticeable with adequate testing. In limited circumstances, this could cause a DoS attack for public contracts under certain conditions.

Patches

Fixed in https://github.com/vyperlang/vyper/pull/2110. Please upgrade to Vyper 0.2.3

Workarounds

Not returning inside a for loop nested 2+ internal calls deep works as is:

@internal
def _baz():
    for i in range(1):
        pass
    return  # This works fine

@internal
def _bar():
    self._baz()

@external
def foo():
    self._bar()

For more information

If you have any questions or comments about this advisory: * Chat with us in our gitter * Open an issue in https://github.com/vyperlang/vyper * Email us at security@vyperlang.org

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "PyPI",
        "name": "vyper"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0.1.0b10"
            },
            {
              "fixed": "0.2.3"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [],
  "database_specific": {
    "cwe_ids": [
      "CWE-691"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-06T15:20:10Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "# VVE-2020-0002\nEarlier today, we received a responsible disclosure of a potential issue from @michwill (developer of @curvefi) for Vyper users who use return statements inside for loops of nested internal calls. Returning inside a for loop causes an invalid jump dest, reverting the transaction unnecessarily.\n\nMWE:\n```python\n@internal\ndef _baz():\n    for i in range(1):\n        return  # Stack underflow happens here\n\n@internal\ndef _bar():\n    self._baz()\n\n@external\ndef foo():\n    self._bar()\n```\n\n### Impact\nImpact is minor, it is unlikely a user would encounter this problem unless they were working with nested calls, and return statements inside calls. Even in that scenario, you would encounter a revert which should be noticeable with adequate testing. In limited circumstances, this could cause a DoS attack for public contracts under certain conditions.\n\n### Patches\nFixed in https://github.com/vyperlang/vyper/pull/2110. Please upgrade to [Vyper 0.2.3](https://pypi.org/project/vyper/)\n\n### Workarounds\nNot returning inside a for loop nested 2+ internal calls deep works as is:\n```python\n@internal\ndef _baz():\n    for i in range(1):\n        pass\n    return  # This works fine\n\n@internal\ndef _bar():\n    self._baz()\n\n@external\ndef foo():\n    self._bar()\n```\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Chat with us in [our gitter ](https://gitter.im/vyperlang/community)\n* Open an issue in [https://github.com/vyperlang/vyper](https://github.com/vyperlang/vyper)\n* Email us at [security@vyperlang.org](mailto:security@vyperlang.org)",
  "id": "GHSA-vg88-3v92-rjx2",
  "modified": "2026-10-06T15:20:11Z",
  "published": "2026-10-06T15:20:10Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/vyperlang/vyper/security/advisories/GHSA-vg88-3v92-rjx2"
    },
    {
      "type": "WEB",
      "url": "https://github.com/vyperlang/vyper/pull/2110"
    },
    {
      "type": "WEB",
      "url": "https://github.com/vyperlang/vyper/commit/a1d92e5eb968a34a23850359656aee23334adb90"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/vyperlang/vyper"
    },
    {
      "type": "WEB",
      "url": "https://github.com/vyperlang/vyper/releases/tag/v0.2.3"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Vyper: Return inside for loop more than 1 level deep"
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…