CVE-2025-26622
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Feb 21, 2025
Updated: Feb 22, 2025
CWE ID 682
Summary
CVE-2025-26622 affects Vyper, a Pythonic Smart Contract Language for the Ethereum Virtual Machine. The issue lies with the `sqrt()` built-in function using the babylonian method to calculate square roots of decimals. Unfortunately, this method may not handle oscillating final states properly, leading to incorrectly rounded up results. Users are advised to upgrade to the expected fix in version 0.4.1 as soon as it becomes available, as there are currently no known workarounds for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Vyper
Affected Vendors
- Vyper