---
id: GHSA-vg88-3v92-rjx2
title: 'Vyper: Return inside for loop more than 1 level deep'
summary: 'Vyper: Return inside for loop more than 1 level deep'
severity: medium
cwe:
  - CWE-691
vendor: vyper
product: vyper
ecosystem: pip
affected:
  - 'vyper >= 0.1.0b10, < 0.2.3'
patched:
  - vyper 0.2.3
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T15:20:13Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-vg88-3v92-rjx2'
references:
  - url: 'https://github.com/vyperlang/vyper/security/advisories/GHSA-vg88-3v92-rjx2'
  - url: 'https://github.com/vyperlang/vyper/pull/2110'
  - url: >-
      https://github.com/vyperlang/vyper/commit/a1d92e5eb968a34a23850359656aee23334adb90
  - url: 'https://github.com/vyperlang/vyper/releases/tag/v0.2.3'
  - url: 'https://github.com/advisories/GHSA-vg88-3v92-rjx2'
tags:
  - ghsa
  - pip
ingestedAt: '2026-10-06T16:04:04.482Z'
---

## Overview

# VVE-2020-0002
Earlier today, we received a responsible disclosure of a potential issue from @michwill (developer of @curvefi) for Vyper users who use return statements inside for loops of nested internal calls. Returning inside a for loop causes an invalid jump dest, reverting the transaction unnecessarily.

MWE:
```python
@internal
def _baz():
    for i in range(1):
        return  # Stack underflow happens here

@internal
def _bar():
    self._baz()

@external
def foo():
    self._bar()
```

### Impact
Impact is minor, it is unlikely a user would encounter this problem unless they were working with nested calls, and return statements inside calls. Even in that scenario, you would encounter a revert which should be noticeable with adequate testing. In limited circumstances, this could cause a DoS attack for public contracts under certain conditions.

### Patches
Fixed in https://github.com/vyperlang/vyper/pull/2110. Please upgrade to [Vyper 0.2.3](https://pypi.org/project/vyper/)

### Workarounds
Not returning inside a for loop nested 2+ internal calls deep works as is:
```python
@internal
def _baz():
    for i in range(1):
        pass
    return  # This works fine

@internal
def _bar():
    self._baz()

@external
def foo():
    self._bar()
```

### For more information
If you have any questions or comments about this advisory:
* Chat with us in [our gitter ](https://gitter.im/vyperlang/community)
* Open an issue in [https://github.com/vyperlang/vyper](https://github.com/vyperlang/vyper)
* Email us at [security@vyperlang.org](mailto:security@vyperlang.org)

## Affected packages

- `vyper >= 0.1.0b10, < 0.2.3`

## Remediation

Upgrade to a patched release:

- `vyper 0.2.3`
