vyper is vulnerable to Unintended Reentrant Invocation of Non-reentrant Code Via Nested Calls
30
Low Risk
Affected versions of this package contain non-reentrant functions that call other non-reentrant functions, leading to race conditions, memory corruption, or undefined behavior when executed in interruptible or concurrent contexts. An attacker could exploit this by forcing re-entry, such as sending a malicious signal while the target function is executing, or by triggering concurrent execution in multi-threaded applications, potentially causing crashes, privilege escalation, or arbitrary code execution due to a corrupted global state.
You are affected if you are using a version that falls within the vulnerable range.
vyper is vulnerable to Unintended Reentrant Invocation of Non-reentrant Code Via Nested Calls in versions 0.4.0 - 0.4.1.
Upgrade the vyper library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant