mediumVulnerability

GHSA-2r3x-4mrv-mcxf

### Impact When performing a function call inside a tuple or as an argument inside another function call, there is a memory corruption issue that occurs because of an incorrect pointer to the the tip of the stack. Example code: ```python @internal def _foo(a: uint256, b: uint256, c: uint256) -> (uint256, uint256, uint256, uint256, uint256): return 1, a, b, c, 5 @internal def _foo2() -> uint256: a: uint256[10] = [6,7,8,9,10,11,12,13,15,16] return 4 @external def foo() -> (uint256, uint256, uint256, uint256, uint256): return self._foo(2, 3, self._foo2()) ``` Please see #2186 for further information ### Patches This problem was fixed in #2186, and released as a part of [`v0.2.6`](https://github.com/vyperlang/vyper/releases/tag/v0.2.6).

Properties

ghsa_id
GHSA-2r3x-4mrv-mcxf
severity
medium
summary
Vyper: Memory corruption using function calls within tuples / nested calls
last_source
GitHub Advisory Database
cve_id
GHSA-2r3x-4mrv-mcxf
signal_observed_at
2026-10-07T00:37:24+00:00
is_ghsa_only
true
retrieved_at
2026-10-07T00:37:24+00:00
ghsa_published
2026-10-06T15:22:29Z
source_url
https://github.com/advisories/GHSA-2r3x-4mrv-mcxf
ghsa_updated
2026-10-06T15:22:30Z

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Improper Validation of Array Index

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]pip/vyper

AFFECTS (1)

→[Software]pip/vyper

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-2r3x-4mrv-mcxf — Ninja Signal Threat Intelligence | Ninja Signal