Bug 2366634 (CVE-2025-47285) - CVE-2025-47285 vyper: Vyper: Zero-Length Bytestring Side-Effect Skipping
Summary: CVE-2025-47285 vyper: Vyper: Zero-Length Bytestring Side-Effect Skipping
Keywords:
Status: NEW
Alias: CVE-2025-47285
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2366742 2366743
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-05-15 18:01 UTC by OSIDB Bzimport
Modified: 2025-05-16 17:33 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-05-15 18:01:35 UTC
Vyper is the Pythonic Programming Language for the Ethereum Virtual Machine. In versions up to and including 0.4.2rc1, `concat()` may skip evaluation of side effects when the length of an argument is zero. This is due to a fastpath in the implementation which skips evaluation of argument expressions when their length is zero. In practice, it would be very unusual in user code to construct zero-length bytestrings using an expression with side-effects, since zero-length bytestrings are typically constructed with the empty literal `b""`; the only way to construct an empty bytestring which has side effects would be with the ternary operator introduced in v0.3.8, e.g. `b"" if self.do_some_side_effect() else b""`. The fix is available in pull request 4644 and expected to be part of the 0.4.2 release. As a workaround, don't have side effects in expressions which construct zero-length bytestrings.


Note You need to log in before you can comment on or make changes to this bug.