vyper is vulnerable to Unintended Reentrant Invocation of Non-reentrant Code Via Nested Calls
30
Low Risk
Affected versions of this package contain non-reentrant functions that call other non-reentrant functions, leading to race conditions, memory corruption, or undefined behavior when executed in interruptible or concurrent contexts. An attacker could exploit this by forcing re-entry, such as sending a malicious signal while the target function is executing, or by triggering concurrent execution in multi-threaded applications, potentially causing crashes, privilege escalation, or arbitrary code execution due to a corrupted global state.
You are affected if you are using a version that falls within the vulnerable range.
vyper is vulnerable to Unintended Reentrant Invocation of Non-reentrant Code Via Nested Calls in versions 0.4.0 - 0.4.1.
Upgrade the vyper library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant