VVE-2021-0001: Memory corruption using function calls within arraysGHSA-22wc-c9wj-6q2v
Fix: vyperlang/vyper#2345GHSA-22wc-c9wj-6q2v is a remote code execution vulnerability in vyper. A fix is available for vyper — see the affected versions and patch details below.
Real-World Exposure
vyperReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.
Description
Impact
When performing a function call inside an array, there is a memory corruption issue that occurs because of an incorrect pointer to the the tip of the stack.
Patches
This issue was partially fixed in VVE-2020-0004, however the fix did not update similar code for arrays, which had a similar issue. The issue is fully fixed in https://github.com/vyperlang/vyper/pull/2345
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐍PyPI | vyper | all versions | 0.2.12pip install --upgrade 'vyper==0.2.12' |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for vyper, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update vyper to 0.2.12 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-22wc-c9wj-6q2v is resolved across your whole dependency graph.
Workarounds
Constrain what reaches the vulnerable code: limit the size and shape of untrusted input, isolate the affected component in a sandboxed or least-privileged process, and enable the platform's memory-safety mitigations (ASLR, stack protector, hardened allocator) so an out-of-bounds access is more likely to fail closed than to be exploitable.
Frequently Asked Questions
Is GHSA-22wc-c9wj-6q2v in your dependencies?
Find it across PyPI, including transitive dependencies.