Vyper is a pythonic Smart Contract... CVE-2024-26149

- AV AC AU C I A
发布: 2024-02-26
修订: 2025-01-16

Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an excessively large value is specified as the starting index for an array in `_abi_decode`, it can cause the read position to overflow. This results in the decoding of values outside the intended array bounds, potentially leading to exploitations in contracts that use arrays within `_abi_decode`. This vulnerability affects 0.3.10 and earlier versions.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息