{"id":"CVE-2023-42441","aliases":["GHSA-3hg2-r75x-g69m","PYSEC-2023-305"],"title":"Vyper has incorrect re-entrancy lock when key is empty string","summary":"Vyper has incorrect re-entrancy lock when key is empty string","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","vendor":"vyper","product":"vyper","ecosystem":"pip","affected":["vyper >= 0.2.9, < 0.3.10"],"patched":["vyper 0.3.10"],"published":"2023-09-18","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:03.191650148Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-3hg2-r75x-g69m","references":[{"url":"https://github.com/vyperlang/vyper/security/advisories/GHSA-3hg2-r75x-g69m"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-42441"},{"url":"https://github.com/vyperlang/vyper/pull/3605"},{"url":"https://github.com/vyperlang/vyper/commit/0b740280c1e3c5528a20d47b29831948ddcc6d83"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/vyper/PYSEC-2023-305.yaml"},{"url":"https://github.com/vyperlang/vyper"}],"tags":["osv","pip"],"epss":0.00514,"epssPercentile":0.42604,"ingestedAt":"2026-09-12T03:13:01.646Z","slug":"CVE-2023-42441","body":"## Overview\n\n### Impact\n\nLocks of the type `@nonreentrant(\"\")` or `@nonreentrant('')` do not produce reentrancy checks at runtime.\n\n```Vyper\n@nonreentrant(\"\") # unprotected\n@external\ndef bar():\n    pass\n\n@nonreentrant(\"lock\") # protected\n@external\ndef foo():\n    pass\n```\n### Patches\n\nPatched in #3605\n\n### Workarounds\n\nThe lock name should be a non-empty string.\n\n### References\n_Are there any links users can visit to find out more?_\n\n\n## Affected packages\n\n- `vyper >= 0.2.9, < 0.3.10`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `vyper 0.3.10`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}