{"id":"GHSA-2r3x-4mrv-mcxf","title":"Vyper: Memory corruption using function calls within tuples / nested calls","summary":"Vyper: Memory corruption using function calls within tuples / nested calls","severity":"medium","cwe":["CWE-129"],"vendor":"vyper","product":"vyper","ecosystem":"pip","affected":["vyper < 0.2.6"],"patched":["vyper 0.2.6"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T15:22:30Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-2r3x-4mrv-mcxf","references":[{"url":"https://github.com/vyperlang/vyper/security/advisories/GHSA-2r3x-4mrv-mcxf"},{"url":"https://github.com/vyperlang/vyper/pull/2186"},{"url":"https://github.com/vyperlang/vyper/commit/74ba67d4bec5f8be4f05759e37d2bfb1463e0441"},{"url":"https://github.com/vyperlang/vyper/releases/tag/v0.2.6"},{"url":"https://github.com/advisories/GHSA-2r3x-4mrv-mcxf"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-06T16:04:04.481Z","slug":"GHSA-2r3x-4mrv-mcxf","body":"## Overview\n\n### Impact\nWhen performing a function call inside a tuple or as an argument inside another function call, there is a memory corruption issue that occurs because of an incorrect pointer to the the tip of the stack.\n\nExample code:\n```python\n@internal\ndef _foo(a: uint256, b: uint256, c: uint256) -> (uint256, uint256, uint256, uint256, uint256):\n    return 1, a, b, c, 5\n\n@internal\ndef _foo2() -> uint256:\n    a: uint256[10] = [6,7,8,9,10,11,12,13,15,16]\n    return 4\n\n@external\ndef foo() -> (uint256, uint256, uint256, uint256, uint256):\n    return self._foo(2, 3, self._foo2())\n```\n\nPlease see #2186 for further information\n\n### Patches\nThis problem was fixed in #2186, and released as a part of [`v0.2.6`](https://github.com/vyperlang/vyper/releases/tag/v0.2.6).\n\n## Affected packages\n\n- `vyper < 0.2.6`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `vyper 0.2.6`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}