CVE detail
CVE-2025-14957
A vulnerability was identified in WebAssembly Binaryen up to 125. This affects the function IRBuilder::makeLocalGet/IRBuilder::makeLocalSet/IRBuilder::makeLocalTee of the file src/wasm/wasm-ir-builder.cpp of the component IRBuilder. Such manipulation of the argument Index leads to null pointer dereference. Local access is required to approach this attack. The exploit is publicly available and might be used. The name of the patch is 6fb2b917a79578ab44cf3b900a6da4c27251e0d4. Applying a patch is advised to resolve this issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
- https://vuldb.com/?submit.717319vuldb.com
No excerpt available.
Exploitvuldb.comDec 19, 2025, 5:15 PM - https://vuldb.com/?submit.717317vuldb.com
No excerpt available.
Exploitvuldb.comDec 19, 2025, 5:15 PM - https://vuldb.com/?id.337593vuldb.com
No excerpt available.
Exploitvuldb.comDec 19, 2025, 5:15 PM - https://vuldb.com/?ctiid.337593vuldb.com
No excerpt available.
Exploitvuldb.comDec 19, 2025, 5:15 PM No excerpt available.
Exploitgithub.comDec 19, 2025, 5:15 PMNo excerpt available.
Exploitgithub.comDec 19, 2025, 5:15 PMNo excerpt available.
Exploitgithub.comDec 19, 2025, 5:15 PMNo excerpt available.
Exploitgithub.comDec 19, 2025, 5:15 PM- https://github.com/WebAssembly/binaryen/github.com
No excerpt available.
Exploitgithub.comDec 19, 2025, 5:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- WebAssembly/binaryenHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 25, 2026, 6:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-17500CVSS 6.9 · Medium
A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation result…
- CVE-2026-15690CVSS 1.3 · Low
A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesArray of the file src/client/ua_client_connect.c of the compo…
- CVE-2026-15184CVSS 1.9 · Low
A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file src/dwg.c of the component DWG File Handler. Performing a…
- CVE-2026-14790CVSS 1.9 · Low
A flaw has been found in GPAC 26.02.0. This affects the function nhmldump_send_frame of the file src/filters/write_nhml.c of the component Media File Handler. Executing a manipula…
- CVE-2026-10298CVSS 1.9 · Low
A security flaw has been discovered in ggml-org whisper.cpp up to 1.8.2. This vulnerability affects the function whisper_model_load of the file ggml/src/ggml.c. The manipulation r…
- CVE-2026-10199CVSS 1.9 · Low
A vulnerability has been found in Assimp up to 6.0.4. Affected by this issue is the function glTF2::LazyDict in the library glTF2Asset.h. Such manipulation of the argument operato…