CVE-2025-47774

Description

A vulnerability has been discovered in the Vyper programming language related to the slice() builtin function. Specifically, when the length argument of slice() is zero and the source bytestring is a builtin like msg.data or

.code, any side effects intended within the start argument may be unintentionally skipped or 'elided'. This could lead to unexpected behavior in smart contract execution, potentially bypassing critical logic or state changes.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Understanding the Weakness (CWE)

Other

Technical Impact: Alter Execution Logic

Frequently Asked Questions

Want to get errata notifications? Sign up here.