Skip to main content

Vendor archive

bytecodealliance CVEs

Beta · best-effort

54 CVEs tagged to vendor bytecodealliance3 Critical, 10 High, 26 Medium, 15 Low, 0 Unrated.

CVE-2025-53901

Published Jul 18, 2025

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation of the WASIp1 set of import functions can lead to a WebAsse…

CVSS 3.5 · Low
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2025-43853

Published May 15, 2025

The WebAssembly Micro Runtime's (WAMR) iwasm package is the executable binary built with WAMR VMcore which supports WebAssembly System Interface (WASI) and command line interface.…

CVSS 7.0 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-51745

Published Nov 5, 2024

Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "L…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-47813

Published Oct 9, 2024

Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistratio…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-47763

Published Oct 9, 2024

Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with stack traces can result in a runtime crash in certain WebAsse…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30266

Published Apr 4, 2024

wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-52284

Published Dec 31, 2023

Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41880

Published Sep 15, 2023

Wasmtime is a standalone runtime for WebAssembly. Wasmtime versions from 10.0.0 to versions 10.02, 11.0.2, and 12.0.1 contain a miscompilation of the WebAssembly `i64x2.shr_s` ins…

CVSS 2.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-30624

Published Apr 27, 2023

Wasmtime is a standalone runtime for WebAssembly. Prior to versions 6.0.2, 7.0.1, and 8.0.1, Wasmtime's implementation of managing per-instance state, such as tables and memories,…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-39394

Published Nov 10, 2022

Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's C API implementation where the definition of the `wasmtime_trap_code` does n…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-39393

Published Nov 10, 2022

Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator where when a lin…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39392

Published Nov 10, 2022

Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator when the allocator is confi…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24791

Published Mar 31, 2022

Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnerability in Wasmtime when both running Wasm that uses externrefs and en…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23636

Published Feb 16, 2022

Wasmtime is an open source runtime for WebAssembly & WASI. Prior to versions 0.34.1 and 0.33.1, there exists a bug in the pooling instance allocator in Wasmtime's runtime where a…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43790

Published Nov 30, 2021

Lucet is a native WebAssembly compiler and runtime. There is a bug in the main branch of `lucet-runtime` affecting all versions published to crates.io that allows a use-after-free…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 54 CVEsPage 2 of 3