SCA: security update for vyper (GHSA-52xq-j7v9-v4v2)

critical Tenable Cloud Security Plugin ID 421476

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a
signed integer, while they are defined for unsigned integers only. The typechecker doesn't throw when
spotting the usage of an `int` as an index for an array. The typechecker allows the usage of signed
integers to be used as indexes to arrays. The vulnerability is present in different forms in all versions,
including `0.3.10`. For ints, the 2's complement representation is used. Because the array was declared
very large, the bounds checking will pass Negative values will simply be represented as very large
numbers. As of time of publication, a fixed version does not exist. There are three potential
vulnerability classes: unpredictable behavior, accessing inaccessible elements and denial of service.
Class 1: If it is possible to index an array with a negative integer without reverting, this is most
likely not anticipated by the developer and such accesses can cause unpredictable behavior for the
contract. Class 2: If a contract has an invariant in the form `assert index < x`, the developer will
suppose that no elements on indexes `y | y >= x` are accessible. However, by using negative indexes, this
can be bypassed. Class 3: If the index is dependent on the state of the contract, this poses a risk of
denial of service. If the state of the contract can be manipulated in such way that the index will be
forced to be negative, the array access can always revert (because most likely the array won't be declared
extremely large). However, all these the scenarios are highly unlikely. Most likely behavior is a revert
on the bounds check. (CVE-2024-24563)

See Also

https://github.com/advisories/GHSA-52xq-j7v9-v4v2

Plugin Details

Severity: Critical

ID: 421476

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 3/28/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-24563

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/7/2024

Vulnerability Publication Date: 2/7/2024

Reference Information

CVE: CVE-2024-24563

cwe: CWE-129