Skip to content
Latest alertgo-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash
0xCERT
All advisories
Low0xCERT-2026-0168·

Solidity compiler bug SOL-2026-6: Misordered Named Parameters In Require With Custom Errors

Custom error arguments passed to ``require`` using named-parameter syntax are ABI-encoded in call-site order instead of declaration order when compiling via IR. Affects 0.8.26 ≤ solc < 0.8.37.

Vuln-watch · relayed from a public source; see Source & attribution below

Affected chainsEthereum

Summary

Custom error arguments passed to `require` using named-parameter syntax are ABI-encoded in call-site order instead of declaration order when compiling via IR.

Details

When a custom error was passed into the second argument of `require and instantiated using named parameter syntax (e.g., require(condition, MyError({b: 1, a: 2}))), the IR-based code generator would pass the arguments to the ABI encoder in the order they appeared at the call site, without reordering them to match the error definition. The arguments were type-checked against the parameters with matching names, not the ones they were actually passed into by the codegen, so the bug would not result in a compilation error. Instead, the encoder would produce a structurally valid encoding matching the error signature but not reflecting the values used to instantiate the error. The arguments on the stack would be reordered and possibly reinterpreted as different types by the encoder. In case of reference types, the reinterpretation would result in the content being obtained from wrong offsets in memory, storage or calldata. In some cases large values misinterpreted as offsets or lengths would make the encoder revert due to running out of gas. Types that occupy more than one slot on the stack would further complicate the behavior by leading to not only reordering but also misalignment of argument boundaries. The only unaffected types were string literals, which are not being passed to the encoder through the stack. The bug was specific to custom errors passed as the second argument of require. Standalone revert ErrorName({...})` statements, event emissions, function calls, struct constructor invocations and other constructs supporting named parameters were not affected. The evmasm pipeline was also unaffected.

Affected

  • Solidity compiler (solc), 0.8.26 ≤ solc < 0.8.37

Severity

Low (upstream rating: "very low").

Recommended actions

  • Contracts compiled with an affected solc version: check whether the conditions apply to your code; recompile with solc 0.8.37+
  • Auditors: add this bug to version-specific checklists

Source & attribution

This 0xCERT advisory summarises Solidity compiler bug SOL-2026-6 (MisorderedNamedParametersInRequireWithCustomErrors) from the Solidity team's bug list: https://blog.soliditylang.org/2026/09/10/misordered-named-parameters-in-require-with-custom-errors-bug/.

OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.

Published 2026-09-10 · last updated 2026-10-08

curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0168/signed.txt | gpg --verify