Webassembly / Wabt
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-90648 | wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does… | HIGH | 7.1 | Sep 12, 2026 |
| CVE-2025-15412 | WebAssembly wabt wasm-decompile VarName out-of-bounds | MEDIUM | 4.8 | Jan 1, 2026 |
| CVE-2025-15411 | WebAssembly wabt wasm-decompile InsertNode memory corruption | MEDIUM | 4.8 | Jan 1, 2026 |
| CVE-2025-6275 | WebAssembly wabt binary-reader-interp.cc GetFuncOffset use after free | MEDIUM | 4.8 | Jun 19, 2025 |
| CVE-2025-6274 | WebAssembly wabt binary-reader-interp.cc OnDataCount resource consumption | MEDIUM | 4.8 | Jun 19, 2025 |
| CVE-2025-6273 | WebAssembly wabt binary-reader-objdump.cc LogOpcode assertion | MEDIUM | 4.8 | Jun 19, 2025 |
| CVE-2025-3122 | WebAssembly wabt binary-reader-interp.cc BeginFunctionBody null pointer dereference | LOW | 2.3 | Apr 2, 2025 |
| CVE-2025-2584 | WebAssembly wabt binary-reader-interp.cc GetReturnCallDropKeepCount heap-based overflow | LOW | 2.3 | Mar 21, 2025 |
| CVE-2025-2368 | WebAssembly wabt Malformed File binary-reader-interp.cc OnExport heap-based overflow | MEDIUM | 5.3 | Mar 17, 2025 |
| CVE-2023-27119 | WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild. | MEDIUM | 5.5 | Mar 10, 2023 |
| CVE-2022-43283 | wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write. | MEDIUM | 5.5 | Oct 28, 2022 |
| CVE-2022-43282 | wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount. | HIGH | 7.1 | Oct 28, 2022 |
| CVE-2022-43280 | wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount. | HIGH | 7.1 | Oct 28, 2022 |
Showing 1 to 13 of 13 CVEs