---
id: GHSA-4v7v-gqf9-ww2g
title: >-
  Vyper: Call stack corruption when passing complex type containing non-base
  type members as argument
summary: >-
  Vyper: Call stack corruption when passing complex type containing non-base
  type members as argument
severity: medium
cwe:
  - CWE-682
vendor: vyper
product: vyper
ecosystem: pip
affected:
  - vyper < 0.2.6
patched:
  - vyper 0.2.6
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T15:22:24Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-4v7v-gqf9-ww2g'
references:
  - url: 'https://github.com/vyperlang/vyper/security/advisories/GHSA-4v7v-gqf9-ww2g'
  - url: 'https://github.com/vyperlang/vyper/issues/2183'
  - url: 'https://github.com/vyperlang/vyper/pull/2184'
  - url: >-
      https://github.com/vyperlang/vyper/commit/0be02b7331e8febe79d5a4218829c72e30417a29
  - url: 'https://github.com/vyperlang/vyper/releases/tag/v0.2.6'
  - url: 'https://github.com/advisories/GHSA-4v7v-gqf9-ww2g'
tags:
  - ghsa
  - pip
ingestedAt: '2026-10-06T16:04:04.481Z'
---

## Overview

### Impact
When we pass a multi-dimensional array (like `[[1, 2], [3, 4]]`) as an argument to internal/external functions we get incorrect output. This is due to a stack management issue, because it was assumed that the size of each subtype of an array/struct is 32, which is not always correct.

Example code:
```python
@internal
def test_input(arr: int128[2][1], i: int128) -> (int128[2][1], int128):
    return arr, i

@external
def test_values(arr: int128[2][1], i: int128) -> (int128[2][1], int128):
    return self.test_input(arr, i)
```

Please see #2183 for further information

### Patches
This problem was fixed in #2184, and released as a part of [`v0.2.6`](https://github.com/vyperlang/vyper/releases/tag/v0.2.6).

## Affected packages

- `vyper < 0.2.6`

## Remediation

Upgrade to a patched release:

- `vyper 0.2.6`
