{"id":"GHSA-vqgp-4jgj-5j64","summary":"Py-EVM is vulnerable to arbitrary bytecode injection","details":"Py-EVM v0.2.0-alpha.33 allows attackers to make a vm.execute_bytecode call that triggers computation._stack.values with '\"stack\": [100, 100, 0]' where b'\\x' was expected, resulting in an execution failure because of an invalid opcode. This is reportedly related to \"smart contracts can be executed indefinitely without gas being paid.\"","aliases":["CVE-2018-18920","PYSEC-2018-155","PYSEC-2018-96"],"modified":"2026-06-05T18:00:16.155499145Z","published":"2018-11-21T22:23:04Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-119"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:58:10Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-18920"},{"type":"WEB","url":"https://github.com/ethereum/py-evm/issues/1448"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vqgp-4jgj-5j64"},{"type":"PACKAGE","url":"https://github.com/ethereum/py-evm"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/evm-py/PYSEC-2018-155.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/py-evm/PYSEC-2018-96.yaml"},{"type":"WEB","url":"https://twitter.com/AlexanderFisher/status/1060923428641878019"},{"type":"WEB","url":"https://twitter.com/NettaLab/status/1060889400102383617"},{"type":"WEB","url":"https://www.reddit.com/r/ethereum/comments/9vkk2g/netta_labs_claim_to_have_found_a_vulnerability_in/e9d3wyx"}],"affected":[{"package":{"name":"py-evm","ecosystem":"PyPI","purl":"pkg:pypi/py-evm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.2.0a33"}]}],"versions":["0.2.0a1","0.2.0a10","0.2.0a11","0.2.0a12","0.2.0a13","0.2.0a14","0.2.0a15","0.2.0a16","0.2.0a17","0.2.0a18","0.2.0a19","0.2.0a20","0.2.0a21","0.2.0a22","0.2.0a24","0.2.0a25","0.2.0a26","0.2.0a28","0.2.0a29","0.2.0a3","0.2.0a30","0.2.0a31","0.2.0a32","0.2.0a33","0.2.0a5","0.2.0a7","0.2.0a8","0.2.0a9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/11/GHSA-vqgp-4jgj-5j64/GHSA-vqgp-4jgj-5j64.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}