GHSA-vg88-3v92-rjx2: Pip/vyper vulnerability

Published Oct 6, 2026
·
Updated

VVE-2020-0002 Earlier today, we received a responsible disclosure of a potential issue from @michwill (developer of @curvefi) for Vyper users who use return statements inside for loops of nested internal calls. Returning inside a for loop causes an invalid jump dest, reverting the transaction unnecessarily.

MWE: python @internal def baz(): for i in range(1): return # Stack underflow happens here

@internal def bar(): self.baz()

@external def foo(): self.bar()

Impact Impact is minor, it is unlikely a user would encounter this problem unless they were working with nested calls, and return statements inside calls. Even in that scenario, you would encounter a revert which should be noticeable with adequate testing. In limited circumstances, this could cause a DoS attack for public contracts under certain conditions.

Patches Fixed in https://github.com/vyperlang/vyper/pull/2110. Please upgrade to Vyper 0.2.3

Workarounds Not returning inside a for loop nested 2+ internal calls deep works as is: python @internal def baz(): for i in range(1): pass return # This works fine

@internal def bar(): self.baz()

@external def foo(): self.bar()

For more information If you have any questions or comments about this advisory: Chat with us in our gitter Open an issue in https://github.com/vyperlang/vyper Email us at security@vyperlang.org

Affected Software

1 affected componentFixes available
pip/vyper>=0.1.0b10<0.2.3
0.2.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/vyper to a version that resolves this vulnerability.

    Fixed in 0.2.3
  2. Upgrade

    Upgrade Vyper to a version that resolves this vulnerability.

    Fixed in 0.2.3

Event History

Oct 6, 2026
Advisory Published
via GitHub·03:20 PM
Data Sourced
via GitHub·03:20 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which contracts are most likely to be affected?

Contracts that use a return statement inside a for loop in an internal function reached through two or more nested internal calls are affected. The issue is unlikely to be encountered outside that call pattern.

2

What happens when the affected code path executes?

The generated code reaches an invalid jump destination and the transaction reverts unnecessarily due to a stack underflow. For public contracts, this can create a denial-of-service condition in limited circumstances.

3

What can be done if upgrading is not immediately possible?

Avoid returning from inside a for loop when the function is nested two or more internal calls deep. Moving the return outside the loop, such as allowing the loop to complete and returning afterward, avoids the issue.

4

What version includes the fix?

Upgrade to Vyper 0.2.3. The fix was made in the referenced pull request 2110.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203