CVE-2023-42460
published 2023-09-27CVE-2023-42460: Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is nested in an expression. Uses of…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.55%
42.9th percentile
Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is nested in an expression. Uses of `_abi_decode()` can be constructed which allow for bounds checking to be bypassed resulting in incorrect results. This issue has not yet been fixed, but a fix is expected in release `0.3.10`. Users are advised to reference pull request #3626.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vyperlang | vyper | — | — |
| vyperlang | vyper | >= 0.3.4 < 0.3.10 | 0.3.10 |
| vyperlang | vyper | >= 0.3.4 < 0.3.10 | 0.3.10 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-42460: Vyper is a Pythonic Smart Contract Language for the EVM
osv·2023-09-27
CVE-2023-42460 CVE-2023-42460: Vyper is a Pythonic Smart Contract Language for the EVM
Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is nested in an expression. Uses of `_abi_decode()` can be constructed which allow for bounds checking to be bypassed resulting in incorrect results. This issue has not yet been fixed, but a fix is expected in release `0.3.10`. Users are advised to reference pull request #3626.
GHSA
Vyper's `_abi_decode` input not validated in complex expressions
ghsa·2023-09-26
CVE-2023-42460 [MEDIUM] CWE-682 Vyper's `_abi_decode` input not validated in complex expressions
Vyper's `_abi_decode` input not validated in complex expressions
### Impact
`_abi_decode()` does not validate input when it is nested in an expression. the following example gets correctly validated (bounds checked):
```vyper
x: int128 = _abi_decode(slice(msg.data, 4, 32), int128)
```
however, the following example is not bounds checked
```vyper
@external
def abi_decode(x: uint256) -> uint256:
a: uint256 = convert(_abi_decode(slice(msg.data, 4, 32), (uint8)), uint256) + 1
return a # abi_decode(256) returns: 257
```
the issue can be triggered by constructing an example where the output of `_abi_decode` is not internally passed to `make_setter` (an internal codegen routine) or other input validating routine.
### Patches
https://github.com/vyperlang/vyper/pull/3626
### Workarounds
_Is th
OSV
Vyper's `_abi_decode` input not validated in complex expressions
osv·2023-09-26
CVE-2023-42460 [MEDIUM] Vyper's `_abi_decode` input not validated in complex expressions
Vyper's `_abi_decode` input not validated in complex expressions
### Impact
`_abi_decode()` does not validate input when it is nested in an expression. the following example gets correctly validated (bounds checked):
```vyper
x: int128 = _abi_decode(slice(msg.data, 4, 32), int128)
```
however, the following example is not bounds checked
```vyper
@external
def abi_decode(x: uint256) -> uint256:
a: uint256 = convert(_abi_decode(slice(msg.data, 4, 32), (uint8)), uint256) + 1
return a # abi_decode(256) returns: 257
```
the issue can be triggered by constructing an example where the output of `_abi_decode` is not internally passed to `make_setter` (an internal codegen routine) or other input validating routine.
### Patches
https://github.com/vyperlang/vyper/pull/3626
### Workarounds
_Is th
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-09-27
Published