CVE-2023-41052Medium· 5.3▾ Sunlitincorrect order of evaluation of side effects for some builtins
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.5%
Last analysed / modified upstream
The order of evaluation of the arguments of the builtin functions uint256_addmod, uint256_mulmod, ecadd and ecmul does not follow source order.
• For uint256_addmod(a,b,c) and uint256_mulmod(a,b,c), the order is c,a,b.
• For ecadd(a,b) and ecmul(a,b), the order is b,a.
Note that this behaviour is problematic when the evaluation of one of the arguments produces side effects that other arguments depend on.
https://github.com/vyperlang/vyper/pull/3583
When using builtins from the list above, make sure that the arguments of the expression do not produce side effects or, if one does, that no other argument is dependent on those side effects.
vyper < 0.3.10Upgrade to a patched release:
vyper 0.3.10Connected by shared product, vendor, weakness, or advisory.
CVE-2024-24567Medium· 4.8Vyper's raw_call `value=` kwargs not disabled for static and delegate calls
CVE-2023-30629High· 7.5Incorrect success value returned in vyper
CVE-2025-21607LowVyper Does Not Check the Success of Certain Precompile Calls
CVE-2023-32059High· 7.5Vyper vulnerable to incorrect ordering of arguments for kwargs passed to internal calls
CVE-2023-30837High· 7.5vyper vulnerable to storage allocator overflow
CVE-2024-24560Low· 3.7Vyper's external calls can overflow return data to return input buffer