Skip to main content

Vendor archive

webassembly CVEs

Beta · best-effort

45 CVEs tagged to vendor webassembly0 Critical, 6 High, 29 Medium, 10 Low, 0 Unrated.

CVE-2026-8257

Published May 11, 2026

A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn…

CVSS 1.9 · Low
evidence mentions
8
Buzz score
37.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15412

Published Jan 1, 2026

A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompi…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
35.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-15411

Published Jan 1, 2026

A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of th…

CVSS 1.9 · Low
evidence mentions
7
Buzz score
36.3
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-14957

Published Dec 19, 2025

A vulnerability was identified in WebAssembly Binaryen up to 125. This affects the function IRBuilder::makeLocalGet/IRBuilder::makeLocalSet/IRBuilder::makeLocalTee of the file src…

CVSS 1.9 · Low
evidence mentions
9
Buzz score
34.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-14956

Published Dec 19, 2025

A vulnerability was determined in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReader::readExport of the file src/wasm/wasm-binary.cpp. This ma…

CVSS 1.9 · Low
evidence mentions
8
Buzz score
33.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-6275

Published Jun 19, 2025

A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulnerability is the function GetFuncOffset of the file src/inter…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-6274

Published Jun 19, 2025

A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-6273

Published Jun 19, 2025

A vulnerability was found in WebAssembly wabt up to 1.0.37 and classified as problematic. This issue affects the function LogOpcode of the file src/binary-reader-objdump.cc. The m…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-3122

Published Apr 2, 2025

A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file sr…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-2584

Published Mar 21, 2025

A vulnerability was found in WebAssembly wabt 1.0.36. It has been declared as critical. This vulnerability affects the function BinaryReaderInterp::GetReturnCallDropKeepCount of t…

CVSS 2.3 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-2368

Published Mar 17, 2025

A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
31.8
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2020-18382

Published Aug 22, 2023

Heap-buffer-overflow in /src/wasm/wasm-binary.cpp in wasm::WasmBinaryBuilder::visitBlock(wasm::Block*) in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, le…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-18378

Published Aug 22, 2023

A NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, le…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31670

Published May 23, 2023

An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27119

Published Mar 10, 2023

WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27117

Published Mar 10, 2023

WebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27115

Published Mar 10, 2023

WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43282

Published Oct 28, 2022

wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43281

Published Oct 28, 2022

wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size() at /bits/stl_vector.h.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43280

Published Oct 28, 2022

wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 45 CVEsPage 1 of 2