Junglewise Threat Intelligence

CVE-2025-26622: PYSEC-2025-29 - vyper is a Pythonic Smart Contract Language for the EVM. Vyper `sqrt()` builtin uses the babylonian method to calculate square roots of deci

CVE-2025-26622 · Severity: medium · CVSS 4 · Published 2025-02-21

Technologies: Vyper. Vendors: PyPI.

Executive brief

Vyper is a smart contract programming language used to write blockchain applications. The sqrt() function uses an iterative algorithm that may incorrectly round up square root results for certain decimal inputs, potentially causing boundary condition checks in contracts to produce wrong answers. While sqrt() is rarely used, this inconsistency could lead to logical errors in contracts relying on precise mathematical calculations.

Technical details

Vyper's sqrt() builtin function implements the babylonian method to compute square roots of decimal numbers. The algorithm terminates when consecutive iterations are equal or after 256 iterations; however, for certain inputs, the result may oscillate between two values N and N+epsilon (where N² ≤ x < (N+epsilon)²), and the termination condition does not guarantee consistent rounding behavior. An attacker or deployed contract using sqrt() could encounter rounded-up results when rounded-down results are expected, affecting boundary conditions. The function diverges from the isqrt() integer variant, which consistently rounds down. The fix is tracked in pull request #4486 and patched in version 0.4.1.

Affected products

  • Vyper Vyper <=0.4.0

Timeline

  • 2025-02-21: disclosed
  • 2025-02-21: patched: Fixed in version 0.4.1

References

Related threats