CVE-2023-39363 Details
Description
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In versions 0.2.15, 0.2.16 and 0.3.0, named re-entrancy locks are allocated incorrectly. Each function using a named re-entrancy lock gets a unique lock regardless of the key, allowing cross-function re-entrancy in contracts compiled with the susceptible versions. A specific set of conditions is required to result in misbehavior of affected contracts, specifically: a `.vy` contract compiled with `vyper` versions `0.2.15`, `0.2.16`, or `0.3.0`; a primary function that utilizes the `@nonreentrant` decorator with a specific `key` and does not strictly follow the check-effects-interaction pattern (i.e. contains an external call to an untrusted party before storage updates); and a secondary function that utilizes the same `key` and would be affected by the improper state caused by the primary function. Version 0.3.1 contains a fix for this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 3, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/vyperlang/vyper/pull/2439 | CVE | Patch |
| https://github.com/vyperlang/vyper/pull/2514 | CVE | Patch |
| https://github.com/vyperlang/vyper/security/advisories/GHSA-5824-cm3x-3c38 | CVE | ExploitPatchThird Party Advisory |
| https://hackmd.io/@LlamaRisk/BJzSKHNjn | CVE | ExploitThird Party Advisory |
| https://hackmd.io/@vyperlang/HJUgNMhs2 | CVE | ExploitThird Party Advisory |
| https://github.com/vyperlang/vyper/pull/2439 | [email protected] | Patch |
| https://github.com/vyperlang/vyper/pull/2514 | [email protected] | Patch |
| https://github.com/vyperlang/vyper/security/advisories/GHSA-5824-cm3x-3c38 | [email protected] | ExploitPatchThird Party Advisory |
| https://hackmd.io/@LlamaRisk/BJzSKHNjn | [email protected] | ExploitThird Party Advisory |
| https://hackmd.io/@vyperlang/HJUgNMhs2 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vyperlang vyper | 0.2.15 0.2.16 0.3.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Oct 11, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Sep 18, 2023 | CVE Modified | [email protected] |
| Aug 11, 2023 | Initial Analysis | [email protected] |