CVE-2021-41121High· 7.5▾ TwilightMemory corruption when returning a literal struct with a private call inside of it
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
1.0% → 1.1%
When performing a function call inside a literal struct, there is a memory corruption issue that occurs because of an incorrect pointer to the the top of the stack.
0.3.0 / #2447
vyper < 0.3.0Upgrade to a patched release:
vyper 0.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-41122Medium· 4.3missing clamps for decimal args in external functions
CVE-2024-24567Medium· 4.8Vyper's raw_call `value=` kwargs not disabled for static and delegate calls
CVE-2023-30629High· 7.5Incorrect success value returned in vyper
CVE-2025-21607LowVyper Does Not Check the Success of Certain Precompile Calls
CVE-2023-32059High· 7.5Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls
CVE-2023-30837High· 7.5vyper vulnerable to storage allocator overflow