{"id":"CVE-2021-41121","aliases":["GHSA-xv8x-pr4h-73jv","PYSEC-2021-365"],"url":"https://o3.security/vulnerability/CVE-2021-41121","summary":"Memory corruption when returning a literal struct with a private call inside of it","details":"Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions when performing a function call inside a literal struct, there is a memory corruption issue that occurs because of an incorrect pointer to the the top of the stack. This issue has been resolved in version 0.3.0.","published":"2021-10-06T18:15:10.897Z","modified":"2026-07-09T11:24:21.084658Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01074,"percentile":0.61625,"asOf":"2026-07-31"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"vyper","fixedVersion":"0.3.0"}],"fix":{"url":"https://github.com/vyperlang/vyper/pull/2447","label":"vyperlang/vyper#2447"},"references":[{"type":"ADVISORY","url":"https://github.com/vyperlang/vyper/security/advisories/GHSA-xv8x-pr4h-73jv"},{"type":"FIX","url":"https://github.com/vyperlang/vyper/pull/2447"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T11:24:21.084658Z"}}