Junglewise Threat Intelligence

Vyper incorrect returndatasize in pre-EIP-1167 forwarder proxies

Severity: info · CVSS 3.7 · Published 2021-04-19

Technologies: Vyper.

Executive brief

Vyper, a smart contract programming language for Ethereum, has a data handling vulnerability in forwarder proxy contracts deployed before support for the EIP-1167 standard. Depending on how the proxy is used, this can cause either data corruption when returning more than 4096 bytes, or contract calls to fail when they validate the expected response size. The vulnerability only affects contracts deployed using the vulnerable create_forwarder_to function before the patch was released.

Technical details

The vulnerability is an improper data validation issue (CWE-20) in Vyper's create_forwarder_to function, which generates simple forwarder proxy bytecode. Pre-EIP-1167 forwarder proxies incorrectly handle the RETURNDATASIZE opcode, potentially returning data larger than expected (truncating at 4096 bytes). This affects contracts that return more than 4096 bytes and callers that explicitly check for specific return data sizes (like SafeERC20.safeTransfer). The vulnerability requires deployment of a vulnerable proxy contract, then calling functions through it. The patch (PR #2281) upgraded to EIP-1167 style forwarders which properly handle return data size. Users can mitigate by using ABI decoders which truncate correctly, or by using greater-than-or-equal checks instead of exact equality checks on RETURNDATASIZE.

Affected products

  • Vyper Vyper before 0.2.9

Timeline

  • 2021-04-16: disclosed: GitHub advisory published
  • 2021-02-13: patched: EIP-1167 forwarder implementation merged in PR #2281
  • 2021-04-19: other: OSV vulnerability published

References