{"id":"GHSA-vg88-3v92-rjx2","title":"Vyper: Return inside for loop more than 1 level deep","summary":"Vyper: Return inside for loop more than 1 level deep","severity":"medium","cwe":["CWE-691"],"vendor":"vyper","product":"vyper","ecosystem":"pip","affected":["vyper >= 0.1.0b10, < 0.2.3"],"patched":["vyper 0.2.3"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T15:20:13Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-vg88-3v92-rjx2","references":[{"url":"https://github.com/vyperlang/vyper/security/advisories/GHSA-vg88-3v92-rjx2"},{"url":"https://github.com/vyperlang/vyper/pull/2110"},{"url":"https://github.com/vyperlang/vyper/commit/a1d92e5eb968a34a23850359656aee23334adb90"},{"url":"https://github.com/vyperlang/vyper/releases/tag/v0.2.3"},{"url":"https://github.com/advisories/GHSA-vg88-3v92-rjx2"}],"tags":["ghsa","pip"],"ingestedAt":"2026-10-06T16:04:04.482Z","slug":"GHSA-vg88-3v92-rjx2","body":"## Overview\n\n# VVE-2020-0002\nEarlier today, we received a responsible disclosure of a potential issue from @michwill (developer of @curvefi) for Vyper users who use return statements inside for loops of nested internal calls. Returning inside a for loop causes an invalid jump dest, reverting the transaction unnecessarily.\n\nMWE:\n```python\n@internal\ndef _baz():\n    for i in range(1):\n        return  # Stack underflow happens here\n\n@internal\ndef _bar():\n    self._baz()\n\n@external\ndef foo():\n    self._bar()\n```\n\n### Impact\nImpact is minor, it is unlikely a user would encounter this problem unless they were working with nested calls, and return statements inside calls. Even in that scenario, you would encounter a revert which should be noticeable with adequate testing. In limited circumstances, this could cause a DoS attack for public contracts under certain conditions.\n\n### Patches\nFixed in https://github.com/vyperlang/vyper/pull/2110. Please upgrade to [Vyper 0.2.3](https://pypi.org/project/vyper/)\n\n### Workarounds\nNot returning inside a for loop nested 2+ internal calls deep works as is:\n```python\n@internal\ndef _baz():\n    for i in range(1):\n        pass\n    return  # This works fine\n\n@internal\ndef _bar():\n    self._baz()\n\n@external\ndef foo():\n    self._bar()\n```\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Chat with us in [our gitter ](https://gitter.im/vyperlang/community)\n* Open an issue in [https://github.com/vyperlang/vyper](https://github.com/vyperlang/vyper)\n* Email us at [security@vyperlang.org](mailto:security@vyperlang.org)\n\n## Affected packages\n\n- `vyper >= 0.1.0b10, < 0.2.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `vyper 0.2.3`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}