Wasm-Micro-Runtime
Bytecodealliance · 5 CVEs
CVE-2025-64713
HIGH
WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I…
Nov 25, 2025
CVE-2025-64704
MEDIUM
WebAssembly Micro Runtime vulnerable to a segmentation fault in v128.store instruction
Nov 25, 2025
CVE-2025-58749
LOW
WAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode
Sep 16, 2025
CVE-2025-54126
MEDIUM
WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specified
Jul 29, 2025
CVE-2025-43853
HIGH
iwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi feature
May 15, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-64713 | WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode | HIGH | 0.33% | Nov 25, 2025 |
| CVE-2025-64704 | WebAssembly Micro Runtime vulnerable to a segmentation fault in v128.store instruction | MEDIUM | 0.19% | Nov 25, 2025 |
| CVE-2025-58749 | WAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode | LOW | 0.37% | Sep 16, 2025 |
| CVE-2025-54126 | WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specified | MEDIUM | 0.63% | Jul 29, 2025 |
| CVE-2025-43853 | iwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi feature | HIGH | 0.28% | May 15, 2025 |
Showing 1 to 5 of 5 CVEs