CVE Feed

    Dashboard / CVE / CVE-2024-43366

    CVE-2024-43366

    zkvyper is a Vyper compiler. Starting in version 1.3.12 and prior to version 1.5.3, since LLL IR has no Turing-incompletness restrictions, it is compiled to a loop with a much more late exit condition. It leads to a loss of funds or other unwanted behavior if the loop body contains it. However, more real-life use cases like iterating over an array are not affected. No contracts were affected by this issue, which was fixed in version 1.5.3. Upgrading and redeploying affected contracts is the only way to avoid the vulnerability.

    Published:Aug 15, 2024
    Last Modified:Sep 27, 2024
    EPS:Aug 15, 2024
    EPSS Score:0.00062
    CVSS Score:7.5

    Affected Products

    Vendor
    Matter-labs
    Product
    Era-compiler-vyper
    Vendor
    Matter-labs
    Product
    Zkvyper

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High