cbcvebase.
CVE-2023-30837
published 2023-05-08

CVE-2023-30837: Vyper is a pythonic smart contract language for the EVM. The storage allocator does not guard against allocation overflows in versions prior to 0.3.8. An…

PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.70%
48.9th percentile
Vyper is a pythonic smart contract language for the EVM. The storage allocator does not guard against allocation overflows in versions prior to 0.3.8. An attacker can overwrite the owner variable. This issue was fixed in version 0.3.8.

Affected

3 ranges
VendorProductVersion rangeFixed in
vyperlangvyper< 0.3.80.3.8
vyperlangvyper>= 0 < 0.3.80.3.8
vyperlangvyper>= 0 < 0bb7203b584e771b23536ba065a6efda457161bb0bb7203b584e771b23536ba065a6efda457161bb
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.