CVE-2024-26149
Vyperlang
CVE-2024-26149 is a vulnerability in Vyper, a smart contract language for the Ethereum Virtual Machine. This vulnerability can lead to out-of-bounds reads in smart contracts that use arrays within the _abi_decode
function. Specifically, an excessively large starting index for an array can cause the read position to overflow, resulting in values being decoded from outside the intended array bounds. This issue impacts Vyper versions 0.3.10 and earlier.
The CVSS score is 5.3, while the SOCRadar Vulnerability Risk Score (SVRS) is 30, indicating a lower immediate risk compared to critical vulnerabilities but should still be monitored. Exploitation of this vulnerability could lead to unpredictable contract behavior and potential security breaches. While the SVRS is not critical, the fact that it's tagged "In The Wild" warrants heightened vigilance and a prompt update to a patched version of Vyper. This vulnerability is important because it could allow attackers to manipulate smart contract execution in unexpected ways.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.