CVE detail
CVE-2026-8257
A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion. The attack needs to be approached locally. The exploit is now public and may be used. The patch is named 1251efbc1ea471c1311d2726b2bbe061ff2a291c. It is suggested to install a patch to address this issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 9.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://vuldb.com/vuln/362554/ctivuldb.com
No excerpt available.
Exploitvuldb.comMay 11, 2026, 2:16 AM - https://vuldb.com/vuln/362554vuldb.com
No excerpt available.
Exploitvuldb.comMay 11, 2026, 2:16 AM - https://vuldb.com/submit/809552vuldb.com
No excerpt available.
Exploitvuldb.comMay 11, 2026, 2:16 AM No excerpt available.
Exploitgithub.comMay 11, 2026, 2:16 AMNo excerpt available.
Exploitgithub.comMay 11, 2026, 2:16 AMNo excerpt available.
Exploitgithub.comMay 11, 2026, 2:16 AM- https://github.com/WebAssembly/binaryen/github.com
No excerpt available.
Exploitgithub.comMay 11, 2026, 2:16 AM No excerpt available.
Exploitgithub.comMay 11, 2026, 2:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
2 repository references · best confidence 0.90 · max 0 stars
- WebAssembly/binaryenHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 20, 2026, 6:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
- HackC0der/CVE-ReposHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 20, 2026, 6:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-46055CVSS 5.5 · Medium
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).
- CVE-2021-46054CVSS 5.5 · Medium
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).
- CVE-2021-46052CVSS 5.5 · Medium
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::Tuple::validate.
- CVE-2021-46048CVSS 5.5 · Medium
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::readFunctions.
- CVE-2021-45290CVSS 7.5 · High
A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.
- CVE-2019-15758CVSS 6.5 · Medium
An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at wasm/wasm.cpp in wasm::asmangle. A crafted input ca…