GHSA-4v7v-gqf9-ww2g
### Impact When we pass a multi-dimensional array (like `[[1, 2], [3, 4]]`) as an argument to internal/external functions we get incorrect output. This is due to a stack management issue, because it was assumed that the size of each subtype of an array/struct is 32, which is not always correct. Example code: ```python @internal def test_input(arr: int128[2][1], i: int128) -> (int128[2][1], int128): return arr, i @external def test_values(arr: int128[2][1], i: int128) -> (int128[2][1], int128): return self.test_input(arr, i) ``` Please see #2183 for further information ### Patches This problem was fixed in #2184, and released as a part of [`v0.2.6`](https://github.com/vyperlang/vyper/releases/tag/v0.2.6).
Properties
- ghsa_id
- GHSA-4v7v-gqf9-ww2g
- severity
- medium
- summary
- Vyper: Call stack corruption when passing complex type containing non-base type members as argument
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-4v7v-gqf9-ww2g
- signal_observed_at
- 2026-10-07T00:37:24+00:00
- is_ghsa_only
- true
- retrieved_at
- 2026-10-07T00:37:24+00:00
- ghsa_published
- 2026-10-06T15:22:23Z
- source_url
- https://github.com/advisories/GHSA-4v7v-gqf9-ww2g
- ghsa_updated
- 2026-10-06T15:22:24Z
Related Entities (4)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph