{"id":"GHSA-4v7v-gqf9-ww2g","title":"Vyper: Call stack corruption when passing complex type containing non-base type members as argument","summary":"Vyper: Call stack corruption when passing complex type containing non-base type members as argument","severity":"medium","cwe":["CWE-682"],"vendor":"vyper","product":"vyper","ecosystem":"pip","affected":["vyper < 0.2.6"],"patched":["vyper 0.2.6"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T15:22:24Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-4v7v-gqf9-ww2g","references":[{"url":"https://github.com/vyperlang/vyper/security/advisories/GHSA-4v7v-gqf9-ww2g"},{"url":"https://github.com/vyperlang/vyper/issues/2183"},{"url":"https://github.com/vyperlang/vyper/pull/2184"},{"url":"https://github.com/vyperlang/vyper/commit/0be02b7331e8febe79d5a4218829c72e30417a29"},{"url":"https://github.com/vyperlang/vyper/releases/tag/v0.2.6"},{"url":"https://github.com/advisories/GHSA-4v7v-gqf9-ww2g"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-06T16:04:04.481Z","slug":"GHSA-4v7v-gqf9-ww2g","body":"## Overview\n\n### Impact\nWhen we pass a multi-dimensional array (like `[[1, 2], [3, 4]]`) as an argument to internal/external functions we get incorrect output. This is due to a stack management issue, because it was assumed that the size of each subtype of an array/struct is 32, which is not always correct.\n\nExample code:\n```python\n@internal\ndef test_input(arr: int128[2][1], i: int128) -> (int128[2][1], int128):\n    return arr, i\n\n@external\ndef test_values(arr: int128[2][1], i: int128) -> (int128[2][1], int128):\n    return self.test_input(arr, i)\n```\n\nPlease see #2183 for further information\n\n### Patches\nThis problem was fixed in #2184, and released as a part of [`v0.2.6`](https://github.com/vyperlang/vyper/releases/tag/v0.2.6).\n\n## Affected packages\n\n- `vyper < 0.2.6`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `vyper 0.2.6`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}