Safety vulnerability ID: 42051
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Vyper version 0.3.0 includes a fix for CVE-2021-41122: In affected versions, external functions don't properly validate the bounds of decimal arguments. That can lead to logic errors.
https://github.com/vyperlang/vyper/security/advisories/GHSA-c7pr-343r-5c46
https://github.com/vyperlang/vyper/pull/2447
Latest version: 0.4.0
Vyper: the Pythonic Programming Language for the EVM
Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions external functions did not properly validate the bounds of decimal arguments. The can lead to logic errors. This issue has been resolved in version 0.3.0. See CVE-2021-41122.
CONFIRM:https://github.com/vyperlang/vyper/security/advisories/GHSA-c7pr-343r-5c46: https://github.com/vyperlang/vyper/security/advisories/GHSA-c7pr-343r-5c46
MISC:https://github.com/vyperlang/vyper/pull/2447: https://github.com/vyperlang/vyper/pull/2447
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application