{"schema_version":1,"title":"vyper (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 42 vulnerabilities in vyper (PyPI): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-47774, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/vyper","json_url":"https://junglewise.ai/threats/technologies/vyper.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/vyper","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":42,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":2},"latest":[{"cve":"CVE-2025-47774","cvss":4,"epss":0.0046,"slug":"cve-2025-47774-vyper-s-slice-may-elide-side-effects-when-output-length-is-0","title":"PYSEC-2026-2028 - Vyper's `slice()` may elide side-effects when output length is 0","severity":"medium","exploited":false,"published_at":"2026-07-07T16:02:52.607813+00:00","url":"https://junglewise.ai/threats/cve-2025-47774-vyper-s-slice-may-elide-side-effects-when-output-length-is-0"},{"cve":"CVE-2025-47285","cvss":4,"epss":0.0045,"slug":"cve-2025-47285-vyper-s-concat-builtin-may-elide-side-effects-for-zero-length","title":"PYSEC-2026-2029 - Vyper's `concat()` builtin may elide side-effects for zero-length arguments","severity":"medium","exploited":false,"published_at":"2026-07-07T16:02:52.484672+00:00","url":"https://junglewise.ai/threats/cve-2025-47285-vyper-s-concat-builtin-may-elide-side-effects-for-zero-length"},{"cve":"CVE-2025-27104","cvss":4,"epss":0.0045,"slug":"cve-2025-27104-vyper-has-a-double-eval-in-for-list-iter","title":"PYSEC-2025-30 - vyper is a Pythonic Smart Contract Language for the EVM. Multiple evaluation of a single expression is possible in the iterator target of a","severity":"medium","exploited":false,"published_at":"2025-02-21T22:15:13+00:00","url":"https://junglewise.ai/threats/cve-2025-27104-vyper-has-a-double-eval-in-for-list-iter"},{"cve":"CVE-2025-26622","cvss":4,"epss":0.0033,"slug":"cve-2025-26622-vyper-sqrt-improper-rounding-behavior-in-decimal-calculations","title":"PYSEC-2025-29 - vyper is a Pythonic Smart Contract Language for the EVM. Vyper `sqrt()` builtin uses the babylonian method to calculate square roots of deci","severity":"medium","exploited":false,"published_at":"2025-02-21T22:15:13+00:00","url":"https://junglewise.ai/threats/cve-2025-26622-vyper-sqrt-improper-rounding-behavior-in-decimal-calculations"},{"cve":"CVE-2025-27105","cvss":4,"epss":0.0057,"slug":"cve-2025-27105-augassign-evaluation-order-causing-oob-write-within-the-object-in","title":"PYSEC-2025-31 - vyper is a Pythonic Smart Contract Language for the EVM. Vyper handles AugAssign statements by first caching the target location to avoid do","severity":"medium","exploited":false,"published_at":"2025-02-21T22:15:13+00:00","url":"https://junglewise.ai/threats/cve-2025-27105-augassign-evaluation-order-causing-oob-write-within-the-object-in"},{"cve":"CVE-2025-21607","cvss":4,"epss":0.0065,"slug":"cve-2025-21607-vyper-does-not-check-the-success-of-certain-precompile-calls","title":"PYSEC-2025-33 - Vyper is a Pythonic Smart Contract Language for the EVM. When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), th","severity":"medium","exploited":false,"published_at":"2025-01-14T18:16:05+00:00","url":"https://junglewise.ai/threats/cve-2025-21607-vyper-does-not-check-the-success-of-certain-precompile-calls"},{"cve":"CVE-2024-32648","cvss":3.1,"epss":0.0042,"slug":"cve-2024-32648-vyper-default-functions-don-t-respect-nonreentrancy-keys","title":"PYSEC-2024-163 - Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Prior to version 0.3.0, default functions don't respect nonree","severity":"low","exploited":false,"published_at":"2024-04-25T18:15:09+00:00","url":"https://junglewise.ai/threats/cve-2024-32648-vyper-default-functions-don-t-respect-nonreentrancy-keys"},{"cve":"CVE-2024-32649","cvss":3.1,"epss":0.0046,"slug":"cve-2024-32649-vyper-performs-multiple-eval-of-sqrt-argument-built-in","title":"PYSEC-2024-209 - Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `sqrt` builtin can res","severity":"low","exploited":false,"published_at":"2024-04-25T18:15:09+00:00","url":"https://junglewise.ai/threats/cve-2024-32649-vyper-performs-multiple-eval-of-sqrt-argument-built-in"},{"cve":"CVE-2024-32645","cvss":3.1,"epss":0.0046,"slug":"cve-2024-32645-vyper-performs-incorrect-topic-logging-in-raw-log","title":"PYSEC-2024-206 - Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect values can be logged w","severity":"low","exploited":false,"published_at":"2024-04-25T18:15:08+00:00","url":"https://junglewise.ai/threats/cve-2024-32645-vyper-performs-incorrect-topic-logging-in-raw-log"},{"cve":"CVE-2024-32647","cvss":3.1,"epss":0.0046,"slug":"cve-2024-32647-vyper-performs-double-eval-of-raw-args-in-create-from-blueprint","title":"PYSEC-2024-208 - Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `create_from_blueprint","severity":"low","exploited":false,"published_at":"2024-04-25T18:15:08+00:00","url":"https://junglewise.ai/threats/cve-2024-32647-vyper-performs-double-eval-of-raw-args-in-create-from-blueprint"},{"cve":"CVE-2024-32646","cvss":3.1,"epss":0.0046,"slug":"cve-2024-32646-vyper-performs-double-eval-of-the-slice-start-length-args-in","title":"PYSEC-2024-207 - Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `slice` builtin can re","severity":"low","exploited":false,"published_at":"2024-04-25T18:15:08+00:00","url":"https://junglewise.ai/threats/cve-2024-32646-vyper-performs-double-eval-of-the-slice-start-length-args-in"},{"cve":"CVE-2024-32481","cvss":3.1,"epss":0.008,"slug":"cve-2024-32481-vyper-s-range-start-start-n-reverts-for-negative-numbers","title":"PYSEC-2024-246 - Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in version 0.3.8 and prior to version 0.4.0b1, when l","severity":"low","exploited":false,"published_at":"2024-04-25T17:15:50+00:00","url":"https://junglewise.ai/threats/cve-2024-32481-vyper-s-range-start-start-n-reverts-for-negative-numbers"},{"cve":"CVE-2024-26149","cvss":3.1,"epss":0.0055,"slug":"cve-2024-26149-vyper-s-abi-decode-vulnerable-to-memory-overflow","title":"PYSEC-2024-164 - Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an excessively large value is specified as the starting ind","severity":"low","exploited":false,"published_at":"2024-02-26T20:19:05+00:00","url":"https://junglewise.ai/threats/cve-2024-26149-vyper-s-abi-decode-vulnerable-to-memory-overflow"},{"cve":"CVE-2024-24564","cvss":3.1,"epss":0.0057,"slug":"cve-2024-24564-vyper-s-extract32-can-ready-dirty-memory","title":"PYSEC-2024-205 - Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, start)`, if the `start`","severity":"low","exploited":false,"published_at":"2024-02-26T20:19:05+00:00","url":"https://junglewise.ai/threats/cve-2024-24564-vyper-s-extract32-can-ready-dirty-memory"},{"cve":"CVE-2024-24563","cvss":3.1,"epss":0.0154,"slug":"cve-2024-24563-vyper-negative-array-index-bounds-checks","title":"PYSEC-2024-150 - Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a signed integer, while they are define","severity":"low","exploited":false,"published_at":"2024-02-07T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-24563-vyper-negative-array-index-bounds-checks"},{"cve":"CVE-2024-24559","cvss":3.1,"epss":0.0026,"slug":"cve-2024-24559-vyper-sha3-codegen-bug","title":"PYSEC-2024-147 - Vyper is a Pythonic Smart Contract Language for the EVM. There is an error in the stack management when compiling the `IR` for `sha3_64`. Co","severity":"low","exploited":false,"published_at":"2024-02-05T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-24559-vyper-sha3-codegen-bug"},{"cve":"CVE-2024-24560","cvss":3.1,"epss":0.0053,"slug":"cve-2024-24560-vyper-s-external-calls-can-overflow-return-data-to-return-input","title":"PYSEC-2024-148 - Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. When calls to external contracts are made, we write the input","severity":"low","exploited":false,"published_at":"2024-02-02T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-24560-vyper-s-external-calls-can-overflow-return-data-to-return-input"},{"cve":"CVE-2024-24561","cvss":3.1,"epss":0.009,"slug":"cve-2024-24561-vyper-s-bounds-check-on-built-in-slice-function-can-be-overflowed","title":"PYSEC-2024-149 - Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices do","severity":"low","exploited":false,"published_at":"2024-02-01T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-24561-vyper-s-bounds-check-on-built-in-slice-function-can-be-overflowed"},{"cve":"CVE-2024-24567","cvss":3.1,"epss":0.0049,"slug":"cve-2024-24567-vyper-s-raw-call-value-kwargs-not-disabled-for-static-and","title":"PYSEC-2024-151 - Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Vyper compiler allows passing a value in builtin raw_call even","severity":"low","exploited":false,"published_at":"2024-01-30T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-24567-vyper-s-raw-call-value-kwargs-not-disabled-for-static-and"},{"cve":"CVE-2024-22419","cvss":3.1,"epss":0.0077,"slug":"cve-2024-22419-vyper-concat-built-in-memory-corruption","title":"PYSEC-2024-103 - Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. The `concat` built-in can write over the bounds of the memory","severity":"low","exploited":false,"published_at":"2024-01-18T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-22419-vyper-concat-built-in-memory-corruption"},{"cve":"CVE-2023-46247","cvss":3.1,"epss":0.007,"slug":"cve-2023-46247-incorrect-storage-layout-for-contracts-containing-large-arrays","title":"PYSEC-2023-307 - Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Contracts containing large arrays might underallocate th","severity":"low","exploited":false,"published_at":"2023-12-13T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-46247-incorrect-storage-layout-for-contracts-containing-large-arrays"},{"cve":"CVE-2023-42460","cvss":3.1,"epss":0.0055,"slug":"cve-2023-42460-vyper-s-abi-decode-input-not-validated-in-complex-expressions","title":"PYSEC-2023-191 - Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is nested in an expres","severity":"low","exploited":false,"published_at":"2023-09-27T15:19:00+00:00","url":"https://junglewise.ai/threats/cve-2023-42460-vyper-s-abi-decode-input-not-validated-in-complex-expressions"},{"cve":"CVE-2023-42443","cvss":3.1,"epss":0.0083,"slug":"cve-2023-42443-vyper-vulnerable-to-memory-corruption-in-certain-builtins","title":"PYSEC-2023-306 - Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In version 0.3.9 and prior, under certain conditions, th","severity":"low","exploited":false,"published_at":"2023-09-18T21:16:00+00:00","url":"https://junglewise.ai/threats/cve-2023-42443-vyper-vulnerable-to-memory-corruption-in-certain-builtins"},{"cve":"CVE-2023-42441","cvss":3.1,"epss":0.0051,"slug":"cve-2023-42441-vyper-reentrancy-lock-bypass-with-empty-string-key","title":"PYSEC-2023-305 - Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). Starting in version 0.2.9 and prior to version 0.3.10, l","severity":"low","exploited":false,"published_at":"2023-09-18T21:16:00+00:00","url":"https://junglewise.ai/threats/cve-2023-42441-vyper-reentrancy-lock-bypass-with-empty-string-key"},{"cve":"CVE-2023-40015","cvss":3.1,"epss":0.0049,"slug":"cve-2023-40015-vyper-reversed-order-of-side-effects-for-some-operations","title":"PYSEC-2023-167 - Vyper is a Pythonic Smart Contract Language. For the following (probably non-exhaustive) list of expressions, the compiler evaluates the arg","severity":"low","exploited":false,"published_at":"2023-09-04T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-40015-vyper-reversed-order-of-side-effects-for-some-operations"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"vyper (PyPI)","slug":"vyper","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://vyper.readthedocs.io","description":"Pythonic smart contract programming language compiling to Ethereum bytecode.","url":"https://junglewise.ai/threats/technologies/vyper"},"most_severe":[{"cve":"CVE-2023-41052","cvss":5.3,"epss":0.0054,"slug":"cve-2023-41052-vyper-incorrect-order-of-evaluation-of-side-effects-in-builtins","title":"Vyper incorrect order of evaluation of side effects in builtins","severity":"medium","exploited":false,"published_at":"2023-09-04T16:39:49+00:00","url":"https://junglewise.ai/threats/cve-2023-41052-vyper-incorrect-order-of-evaluation-of-side-effects-in-builtins"},{"cve":"CVE-2025-21607","cvss":4,"epss":0.0065,"slug":"cve-2025-21607-vyper-does-not-check-the-success-of-certain-precompile-calls","title":"PYSEC-2025-33 - Vyper is a Pythonic Smart Contract Language for the EVM. When the Vyper Compiler uses the precompiles EcRecover (0x1) and Identity (0x4), th","severity":"medium","exploited":false,"published_at":"2025-01-14T18:16:05+00:00","url":"https://junglewise.ai/threats/cve-2025-21607-vyper-does-not-check-the-success-of-certain-precompile-calls"},{"cve":"CVE-2025-27105","cvss":4,"epss":0.0057,"slug":"cve-2025-27105-augassign-evaluation-order-causing-oob-write-within-the-object-in","title":"PYSEC-2025-31 - vyper is a Pythonic Smart Contract Language for the EVM. Vyper handles AugAssign statements by first caching the target location to avoid do","severity":"medium","exploited":false,"published_at":"2025-02-21T22:15:13+00:00","url":"https://junglewise.ai/threats/cve-2025-27105-augassign-evaluation-order-causing-oob-write-within-the-object-in"},{"cve":"CVE-2025-47774","cvss":4,"epss":0.0046,"slug":"cve-2025-47774-vyper-s-slice-may-elide-side-effects-when-output-length-is-0","title":"PYSEC-2026-2028 - Vyper's `slice()` may elide side-effects when output length is 0","severity":"medium","exploited":false,"published_at":"2026-07-07T16:02:52.607813+00:00","url":"https://junglewise.ai/threats/cve-2025-47774-vyper-s-slice-may-elide-side-effects-when-output-length-is-0"},{"cve":"CVE-2025-47285","cvss":4,"epss":0.0045,"slug":"cve-2025-47285-vyper-s-concat-builtin-may-elide-side-effects-for-zero-length","title":"PYSEC-2026-2029 - Vyper's `concat()` builtin may elide side-effects for zero-length arguments","severity":"medium","exploited":false,"published_at":"2026-07-07T16:02:52.484672+00:00","url":"https://junglewise.ai/threats/cve-2025-47285-vyper-s-concat-builtin-may-elide-side-effects-for-zero-length"},{"cve":"CVE-2025-27104","cvss":4,"epss":0.0045,"slug":"cve-2025-27104-vyper-has-a-double-eval-in-for-list-iter","title":"PYSEC-2025-30 - vyper is a Pythonic Smart Contract Language for the EVM. Multiple evaluation of a single expression is possible in the iterator target of a","severity":"medium","exploited":false,"published_at":"2025-02-21T22:15:13+00:00","url":"https://junglewise.ai/threats/cve-2025-27104-vyper-has-a-double-eval-in-for-list-iter"},{"cve":"CVE-2025-26622","cvss":4,"epss":0.0033,"slug":"cve-2025-26622-vyper-sqrt-improper-rounding-behavior-in-decimal-calculations","title":"PYSEC-2025-29 - vyper is a Pythonic Smart Contract Language for the EVM. Vyper `sqrt()` builtin uses the babylonian method to calculate square roots of deci","severity":"medium","exploited":false,"published_at":"2025-02-21T22:15:13+00:00","url":"https://junglewise.ai/threats/cve-2025-26622-vyper-sqrt-improper-rounding-behavior-in-decimal-calculations"},{"cve":"CVE-2024-24563","cvss":3.1,"epss":0.0154,"slug":"cve-2024-24563-vyper-negative-array-index-bounds-checks","title":"PYSEC-2024-150 - Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a signed integer, while they are define","severity":"low","exploited":false,"published_at":"2024-02-07T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-24563-vyper-negative-array-index-bounds-checks"},{"cve":"CVE-2022-24845","cvss":3.1,"epss":0.0143,"slug":"cve-2022-24845-integer-bounds-error-in-vyper","title":"PYSEC-2022-198 - Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In affected versions, the return of `<iface>.returns_int128()`","severity":"low","exploited":false,"published_at":"2022-04-13T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-24845-integer-bounds-error-in-vyper"},{"cve":"CVE-2022-29255","cvss":3.1,"epss":0.0133,"slug":"cve-2022-29255-multiple-evaluation-of-contract-address-in-call-in-vyper","title":"PYSEC-2022-43053 - Vyper is a Pythonic Smart Contract Language for the ethereum virtual machine. In versions prior to 0.3.4 when a calling an external contract","severity":"low","exploited":false,"published_at":"2022-06-09T09:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-29255-multiple-evaluation-of-contract-address-in-call-in-vyper"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}