mediumVulnerability

GHSA-4v7v-gqf9-ww2g

### Impact When we pass a multi-dimensional array (like `[[1, 2], [3, 4]]`) as an argument to internal/external functions we get incorrect output. This is due to a stack management issue, because it was assumed that the size of each subtype of an array/struct is 32, which is not always correct. Example code: ```python @internal def test_input(arr: int128[2][1], i: int128) -> (int128[2][1], int128): return arr, i @external def test_values(arr: int128[2][1], i: int128) -> (int128[2][1], int128): return self.test_input(arr, i) ``` Please see #2183 for further information ### Patches This problem was fixed in #2184, and released as a part of [`v0.2.6`](https://github.com/vyperlang/vyper/releases/tag/v0.2.6).

Properties

ghsa_id
GHSA-4v7v-gqf9-ww2g
severity
medium
summary
Vyper: Call stack corruption when passing complex type containing non-base type members as argument
last_source
GitHub Advisory Database
cve_id
GHSA-4v7v-gqf9-ww2g
signal_observed_at
2026-10-07T00:37:24+00:00
is_ghsa_only
true
retrieved_at
2026-10-07T00:37:24+00:00
ghsa_published
2026-10-06T15:22:23Z
source_url
https://github.com/advisories/GHSA-4v7v-gqf9-ww2g
ghsa_updated
2026-10-06T15:22:24Z

Related Entities (4)

HAS_WEAKNESS (1)

→[Weakness]Incorrect Calculation

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]pip/vyper

AFFECTS (1)

→[Software]pip/vyper

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-4v7v-gqf9-ww2g — Ninja Signal Threat Intelligence | Ninja Signal