Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vyperlang

First CVE: Oct 5, 2021Active for: 5 yearsTotal CVEs: 38
30.0
VTI Score
Low

Vyper is a domain-specific programming language designed for smart contract development on the Ethereum Virtual Machine, and its vulnerability footprint reflects the safety-critical nature of that role. Vulnerabilities affecting the language's compiler and runtime lean toward serious outcomes, with an elevated share reaching critical severity, reflecting the high stakes of flaws that can result in cryptocurrency loss or contract compromise. The exposure concentrates in the single Vyper product and recurs through weakness classes including control flow implementation errors, buffer-bounds violations, out-of-bounds writes, and incorrect calculations—defects that arise from the compiler's handling of arithmetic, memory layout, and bytecode generation and that can lead to unintended contract behavior when compiled code diverges from developer intent. Defenders and developers using Vyper should treat language and compiler updates as high-priority, particularly where contracts handle significant assets or access controls; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
38
Total CVEs
More Total CVEs than 98% of tracked vendors
7.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vyperlang over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 5, 2021
4 years ago
Most Recent CVE
Feb 21, 2025
518 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-24788CRITICAL
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Versions of vyper prior to 0.3.2 suffer from a potential buffer overrun. Importing a function from a J
Apr 13, 20229.831NONO
CVE-2024-24561CRITICAL
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices does not account for the ability for start
Feb 1, 20249.830NONO
CVE-2024-24563CRITICAL
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a signed integer, while they are defined for unsigned integers only. The typech
Feb 7, 20249.827NONO
CVE-2023-31146CRITICAL
Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, during codegen, the length word of a dynarray is written before the data, whic
May 11, 20239.127NONO
CVE-2021-41121HIGH
Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions when performing a function call inside a literal struct, there is a memory corruption issue that occur
Oct 6, 20218.827NONO
CVE-2025-27105CRITICAL
vyper is a Pythonic Smart Contract Language for the EVM. Vyper handles AugAssign statements by first caching the target location to avoid double evaluation. However, in the case wh
Feb 21, 20259.126NONO
CVE-2024-22419CRITICAL
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. The `concat` built-in can write over the bounds of the memory buffer that was allocated for it and thu
Jan 18, 20249.826NONO
CVE-2022-24787HIGH
Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. In version 0.3.1 and prior, bytestrings can have dirty bytes in them, resulting in the word-for-word c
Apr 4, 20227.525NONO
CVE-2023-32058HIGH
Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, due to missing overflow check for loop variables, by assigning the iterator of
May 11, 20237.524NONO
CVE-2023-30837HIGH
Vyper is a pythonic smart contract language for the EVM. The storage allocator does not guard against allocation overflows in versions prior to 0.3.8. An attacker can overwrite the
May 8, 20237.524NONO
View all 38 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products38 CVEs
47%
34%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network38 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (94.7%)
High2 (5.3%)
Unknown0 (0.0%)
User Interaction
None38 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (5.3%)
High0 (0.0%)
None36 (94.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vyperlang.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vyperlang — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vyperlang's Products

View all 1 CNAs →

Top CWEs