wabt: WebAssembly wabt: Memory corruption vulnerability in wasm-decompile component

cve CVE-2025-15411 2 sources, 2 claims · Watch

Red Hat writes:
wabt: WebAssembly wabt: Memory corruption vulnerability in wasm-decompile component the claim

What it is to other things

affectswebassembly/wabt
NVD
made_bywebassembly
NVD

What each source says

PropertySourceSaidMeans here
Cvss
cvss
conflict
NVD5.3
receipt
Source
NVD
Its words
5.3
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*"
            ],
            "modules": [
              "wasm-decompile"
            ],
            "product": "wabt",
            "vendor": "WebAssembly",
            "versions": [
              {
                "status": "affected",
                "version": "1.0.0"
              },
              {
                "status": "affected",
                "version": "1.0.1"
              },
              {
                "status": "affected",
                "version": "1.0.2"
              },
              {
                "status": "affected",
                "version": "1.0.3"
              },
              {
                "status": "affected",
                "version": "1.0.4"
              },
              {
                "status": "affected",
                "version": "1.0.5"
              },
              {
                "status": "affected",
                "version": "1.0.6"
              },
              {
                "status": "affected",
                "version": "1.0.7"
              },
              {
                "status": "affected",
                "version": "1.0.8"
              },
              {
                "status": "affected",
                "version": "1.0.9"
              },
              {
                "status": "affected",
                "version": "1.0.10"
              },
              {
                "status": "affected",
                "version": "1.0.11"
              },
              {
                "status": "affected",
                "version": "1.0.12"
              },
              {
                "status": "affected",
                "version": "1.0.13"
              },
              {
                "status": "affected",
                "version": "1.0.14"
              },
              {
                "status": "affected",
                "version": "1.0.15"
              },
              {
                "status": "affected",
                "version": "1.0.16"
              },
              {
                "status": "affected",
                "version": "1.0.17"
              },
              {
                "status": "affected",
                "version": "1.0.18"
              },
              {
                "status": "affected",
                "version": "1.0.19"
              },
              {
                "status": "affected",
                "version": "1.0.20"
              },
              {
                "status": "affected",
                "version": "1.0.21"
              },
              {
                "status": "affected",
                "version": "1.0.22"
              },
              {
                "status": "affected",
                "version": "1.0.23"
              },
              {
                "status": "affected",
                "version": "1.0.24"
              },
              {
                "status": "affected",
                "version": "1.0.25"
              },
              {
                "status": "affected",
                "version": "1.0.26"
              },
              {
                "status": "affected",
                "version": "1.0.27"
              },
              {
                "status": "affected",
                "version": "1.0.28"
              },
              {
                "status": "affected",
                "version": "1.0.29"
              },
              {
                "status": "affected",
                "version": "1.0.30"
              },
              {
                "status": "affected",
                "version": "1.0.31"
              },
              {
                "status": "affected",
                "version": "1.0.32"
              },
              {
                "status": "affected",
                "version": "1.0.33"
              },
              {
                "status": "affected",
                "version": "1.0.34"
              },
              {
                "status": "affected",
                "version": "1.0.35"
              },
              {
                "status": "affected",
                "version": "1.0.36"
              },
              {
                "status": "affected",
                "version": "1.0.37"
              },
              {
                "status": "affected",
                "version": "1.0.38"
              },
              {
                "status": "affected",
                "version": "1.0.39"
              }
            ]
          }
        ],
        "source": "cna@vuldb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4553C1EF-0407-4632-ACA5-3D1E2A76FBDA",
                "versionEndIncluding": "1.0.39",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself."
      },
      {
        "lang": "es",
        "value": "Se ha identificado una debilidad en WebAssembly wabt hasta la versión 1.0.39. Esta vulnerabilidad afecta la función wabt::AST::InsertNode del archivo /src/repro/wabt/bin/wasm-decompile del componente wasm-decompile. Esta manipulación causa corrupción de memoria. Es posible lanzar el ataque en el host local. El exploit se ha puesto a disposición del público y podría usarse para ataques. Desafortunadamente, el proyecto no tiene ningún mantenedor activo en este momento. En una respuesta al informe del problema, alguien recomendó al investigador que proporcionara un PR él mismo."
      }
    ],
    "id": "CVE-2025-15411",
    "lastModified": "2026-10-01T08:10:00.183",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "MEDIUM",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "SINGLE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 4.3,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:L/AC:L/Au:S/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "cna@vuldb.com",
          "type": "Secondary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.4,
          "source": "cna@vuldb.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "LOCAL",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.9,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "PROOF_OF_CONCEPT",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@vuldb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-15411",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-05T21:03:24.165884Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-01T20:15:40.640",
    "references": [
      {
        "source": "cna@vuldb.com",
        "url": "https://github.com/WebAssembly/wabt/"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit",
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://github.com/WebAssembly/wabt/issues/2679"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit"
        ],
        "url": "https://github.com/oneafter/1208/blob/main/af1"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Permissions Required",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?ctiid.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?id.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?submit.719825"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/?submit.736404"
      }
    ],
    "sourceIdentifier": "cna@vuldb.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "cna@vuldb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss
cvss
conflict
Red Hat7.1
receipt
Source
Red Hat
Its words
7.1
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-15411",
  "CWE": "CWE-119",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2426683",
  "bugzilla_description": "wabt: WebAssembly wabt: Memory corruption vulnerability in wasm-decompile component",
  "cvss3_score": "7.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-01-01T19:32:07Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-15411.json",
  "severity": "moderate"
}
—
Cwe
cwe
Red HatCWE-119
receipt
Source
Red Hat
Its words
CWE-119
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-15411",
  "CWE": "CWE-119",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2426683",
  "bugzilla_description": "wabt: WebAssembly wabt: Memory corruption vulnerability in wasm-decompile component",
  "cvss3_score": "7.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-01-01T19:32:07Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-15411.json",
  "severity": "moderate"
}
—
Product
product
NVDwabt
receipt
Source
NVD
Its words
wabt
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*"
            ],
            "modules": [
              "wasm-decompile"
            ],
            "product": "wabt",
            "vendor": "WebAssembly",
            "versions": [
              {
                "status": "affected",
                "version": "1.0.0"
              },
              {
                "status": "affected",
                "version": "1.0.1"
              },
              {
                "status": "affected",
                "version": "1.0.2"
              },
              {
                "status": "affected",
                "version": "1.0.3"
              },
              {
                "status": "affected",
                "version": "1.0.4"
              },
              {
                "status": "affected",
                "version": "1.0.5"
              },
              {
                "status": "affected",
                "version": "1.0.6"
              },
              {
                "status": "affected",
                "version": "1.0.7"
              },
              {
                "status": "affected",
                "version": "1.0.8"
              },
              {
                "status": "affected",
                "version": "1.0.9"
              },
              {
                "status": "affected",
                "version": "1.0.10"
              },
              {
                "status": "affected",
                "version": "1.0.11"
              },
              {
                "status": "affected",
                "version": "1.0.12"
              },
              {
                "status": "affected",
                "version": "1.0.13"
              },
              {
                "status": "affected",
                "version": "1.0.14"
              },
              {
                "status": "affected",
                "version": "1.0.15"
              },
              {
                "status": "affected",
                "version": "1.0.16"
              },
              {
                "status": "affected",
                "version": "1.0.17"
              },
              {
                "status": "affected",
                "version": "1.0.18"
              },
              {
                "status": "affected",
                "version": "1.0.19"
              },
              {
                "status": "affected",
                "version": "1.0.20"
              },
              {
                "status": "affected",
                "version": "1.0.21"
              },
              {
                "status": "affected",
                "version": "1.0.22"
              },
              {
                "status": "affected",
                "version": "1.0.23"
              },
              {
                "status": "affected",
                "version": "1.0.24"
              },
              {
                "status": "affected",
                "version": "1.0.25"
              },
              {
                "status": "affected",
                "version": "1.0.26"
              },
              {
                "status": "affected",
                "version": "1.0.27"
              },
              {
                "status": "affected",
                "version": "1.0.28"
              },
              {
                "status": "affected",
                "version": "1.0.29"
              },
              {
                "status": "affected",
                "version": "1.0.30"
              },
              {
                "status": "affected",
                "version": "1.0.31"
              },
              {
                "status": "affected",
                "version": "1.0.32"
              },
              {
                "status": "affected",
                "version": "1.0.33"
              },
              {
                "status": "affected",
                "version": "1.0.34"
              },
              {
                "status": "affected",
                "version": "1.0.35"
              },
              {
                "status": "affected",
                "version": "1.0.36"
              },
              {
                "status": "affected",
                "version": "1.0.37"
              },
              {
                "status": "affected",
                "version": "1.0.38"
              },
              {
                "status": "affected",
                "version": "1.0.39"
              }
            ]
          }
        ],
        "source": "cna@vuldb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4553C1EF-0407-4632-ACA5-3D1E2A76FBDA",
                "versionEndIncluding": "1.0.39",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself."
      },
      {
        "lang": "es",
        "value": "Se ha identificado una debilidad en WebAssembly wabt hasta la versión 1.0.39. Esta vulnerabilidad afecta la función wabt::AST::InsertNode del archivo /src/repro/wabt/bin/wasm-decompile del componente wasm-decompile. Esta manipulación causa corrupción de memoria. Es posible lanzar el ataque en el host local. El exploit se ha puesto a disposición del público y podría usarse para ataques. Desafortunadamente, el proyecto no tiene ningún mantenedor activo en este momento. En una respuesta al informe del problema, alguien recomendó al investigador que proporcionara un PR él mismo."
      }
    ],
    "id": "CVE-2025-15411",
    "lastModified": "2026-10-01T08:10:00.183",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "MEDIUM",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "SINGLE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 4.3,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:L/AC:L/Au:S/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "cna@vuldb.com",
          "type": "Secondary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.4,
          "source": "cna@vuldb.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "LOCAL",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.9,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "PROOF_OF_CONCEPT",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@vuldb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-15411",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-05T21:03:24.165884Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-01T20:15:40.640",
    "references": [
      {
        "source": "cna@vuldb.com",
        "url": "https://github.com/WebAssembly/wabt/"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit",
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://github.com/WebAssembly/wabt/issues/2679"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit"
        ],
        "url": "https://github.com/oneafter/1208/blob/main/af1"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Permissions Required",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?ctiid.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?id.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?submit.719825"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/?submit.736404"
      }
    ],
    "sourceIdentifier": "cna@vuldb.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "cna@vuldb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-15411",
  "CWE": "CWE-119",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2426683",
  "bugzilla_description": "wabt: WebAssembly wabt: Memory corruption vulnerability in wasm-decompile component",
  "cvss3_score": "7.1",
  "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-01-01T19:32:07Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-15411.json",
  "severity": "moderate"
}
medium
Status
status
NVDModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*"
            ],
            "modules": [
              "wasm-decompile"
            ],
            "product": "wabt",
            "vendor": "WebAssembly",
            "versions": [
              {
                "status": "affected",
                "version": "1.0.0"
              },
              {
                "status": "affected",
                "version": "1.0.1"
              },
              {
                "status": "affected",
                "version": "1.0.2"
              },
              {
                "status": "affected",
                "version": "1.0.3"
              },
              {
                "status": "affected",
                "version": "1.0.4"
              },
              {
                "status": "affected",
                "version": "1.0.5"
              },
              {
                "status": "affected",
                "version": "1.0.6"
              },
              {
                "status": "affected",
                "version": "1.0.7"
              },
              {
                "status": "affected",
                "version": "1.0.8"
              },
              {
                "status": "affected",
                "version": "1.0.9"
              },
              {
                "status": "affected",
                "version": "1.0.10"
              },
              {
                "status": "affected",
                "version": "1.0.11"
              },
              {
                "status": "affected",
                "version": "1.0.12"
              },
              {
                "status": "affected",
                "version": "1.0.13"
              },
              {
                "status": "affected",
                "version": "1.0.14"
              },
              {
                "status": "affected",
                "version": "1.0.15"
              },
              {
                "status": "affected",
                "version": "1.0.16"
              },
              {
                "status": "affected",
                "version": "1.0.17"
              },
              {
                "status": "affected",
                "version": "1.0.18"
              },
              {
                "status": "affected",
                "version": "1.0.19"
              },
              {
                "status": "affected",
                "version": "1.0.20"
              },
              {
                "status": "affected",
                "version": "1.0.21"
              },
              {
                "status": "affected",
                "version": "1.0.22"
              },
              {
                "status": "affected",
                "version": "1.0.23"
              },
              {
                "status": "affected",
                "version": "1.0.24"
              },
              {
                "status": "affected",
                "version": "1.0.25"
              },
              {
                "status": "affected",
                "version": "1.0.26"
              },
              {
                "status": "affected",
                "version": "1.0.27"
              },
              {
                "status": "affected",
                "version": "1.0.28"
              },
              {
                "status": "affected",
                "version": "1.0.29"
              },
              {
                "status": "affected",
                "version": "1.0.30"
              },
              {
                "status": "affected",
                "version": "1.0.31"
              },
              {
                "status": "affected",
                "version": "1.0.32"
              },
              {
                "status": "affected",
                "version": "1.0.33"
              },
              {
                "status": "affected",
                "version": "1.0.34"
              },
              {
                "status": "affected",
                "version": "1.0.35"
              },
              {
                "status": "affected",
                "version": "1.0.36"
              },
              {
                "status": "affected",
                "version": "1.0.37"
              },
              {
                "status": "affected",
                "version": "1.0.38"
              },
              {
                "status": "affected",
                "version": "1.0.39"
              }
            ]
          }
        ],
        "source": "cna@vuldb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4553C1EF-0407-4632-ACA5-3D1E2A76FBDA",
                "versionEndIncluding": "1.0.39",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself."
      },
      {
        "lang": "es",
        "value": "Se ha identificado una debilidad en WebAssembly wabt hasta la versión 1.0.39. Esta vulnerabilidad afecta la función wabt::AST::InsertNode del archivo /src/repro/wabt/bin/wasm-decompile del componente wasm-decompile. Esta manipulación causa corrupción de memoria. Es posible lanzar el ataque en el host local. El exploit se ha puesto a disposición del público y podría usarse para ataques. Desafortunadamente, el proyecto no tiene ningún mantenedor activo en este momento. En una respuesta al informe del problema, alguien recomendó al investigador que proporcionara un PR él mismo."
      }
    ],
    "id": "CVE-2025-15411",
    "lastModified": "2026-10-01T08:10:00.183",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "MEDIUM",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "SINGLE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 4.3,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:L/AC:L/Au:S/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "cna@vuldb.com",
          "type": "Secondary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.4,
          "source": "cna@vuldb.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "LOCAL",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.9,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "PROOF_OF_CONCEPT",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@vuldb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-15411",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-05T21:03:24.165884Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-01T20:15:40.640",
    "references": [
      {
        "source": "cna@vuldb.com",
        "url": "https://github.com/WebAssembly/wabt/"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit",
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://github.com/WebAssembly/wabt/issues/2679"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit"
        ],
        "url": "https://github.com/oneafter/1208/blob/main/af1"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Permissions Required",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?ctiid.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?id.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?submit.719825"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/?submit.736404"
      }
    ],
    "sourceIdentifier": "cna@vuldb.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "cna@vuldb.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDWebAssembly
receipt
Source
NVD
Its words
WebAssembly
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*"
            ],
            "modules": [
              "wasm-decompile"
            ],
            "product": "wabt",
            "vendor": "WebAssembly",
            "versions": [
              {
                "status": "affected",
                "version": "1.0.0"
              },
              {
                "status": "affected",
                "version": "1.0.1"
              },
              {
                "status": "affected",
                "version": "1.0.2"
              },
              {
                "status": "affected",
                "version": "1.0.3"
              },
              {
                "status": "affected",
                "version": "1.0.4"
              },
              {
                "status": "affected",
                "version": "1.0.5"
              },
              {
                "status": "affected",
                "version": "1.0.6"
              },
              {
                "status": "affected",
                "version": "1.0.7"
              },
              {
                "status": "affected",
                "version": "1.0.8"
              },
              {
                "status": "affected",
                "version": "1.0.9"
              },
              {
                "status": "affected",
                "version": "1.0.10"
              },
              {
                "status": "affected",
                "version": "1.0.11"
              },
              {
                "status": "affected",
                "version": "1.0.12"
              },
              {
                "status": "affected",
                "version": "1.0.13"
              },
              {
                "status": "affected",
                "version": "1.0.14"
              },
              {
                "status": "affected",
                "version": "1.0.15"
              },
              {
                "status": "affected",
                "version": "1.0.16"
              },
              {
                "status": "affected",
                "version": "1.0.17"
              },
              {
                "status": "affected",
                "version": "1.0.18"
              },
              {
                "status": "affected",
                "version": "1.0.19"
              },
              {
                "status": "affected",
                "version": "1.0.20"
              },
              {
                "status": "affected",
                "version": "1.0.21"
              },
              {
                "status": "affected",
                "version": "1.0.22"
              },
              {
                "status": "affected",
                "version": "1.0.23"
              },
              {
                "status": "affected",
                "version": "1.0.24"
              },
              {
                "status": "affected",
                "version": "1.0.25"
              },
              {
                "status": "affected",
                "version": "1.0.26"
              },
              {
                "status": "affected",
                "version": "1.0.27"
              },
              {
                "status": "affected",
                "version": "1.0.28"
              },
              {
                "status": "affected",
                "version": "1.0.29"
              },
              {
                "status": "affected",
                "version": "1.0.30"
              },
              {
                "status": "affected",
                "version": "1.0.31"
              },
              {
                "status": "affected",
                "version": "1.0.32"
              },
              {
                "status": "affected",
                "version": "1.0.33"
              },
              {
                "status": "affected",
                "version": "1.0.34"
              },
              {
                "status": "affected",
                "version": "1.0.35"
              },
              {
                "status": "affected",
                "version": "1.0.36"
              },
              {
                "status": "affected",
                "version": "1.0.37"
              },
              {
                "status": "affected",
                "version": "1.0.38"
              },
              {
                "status": "affected",
                "version": "1.0.39"
              }
            ]
          }
        ],
        "source": "cna@vuldb.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "4553C1EF-0407-4632-ACA5-3D1E2A76FBDA",
                "versionEndIncluding": "1.0.39",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself."
      },
      {
        "lang": "es",
        "value": "Se ha identificado una debilidad en WebAssembly wabt hasta la versión 1.0.39. Esta vulnerabilidad afecta la función wabt::AST::InsertNode del archivo /src/repro/wabt/bin/wasm-decompile del componente wasm-decompile. Esta manipulación causa corrupción de memoria. Es posible lanzar el ataque en el host local. El exploit se ha puesto a disposición del público y podría usarse para ataques. Desafortunadamente, el proyecto no tiene ningún mantenedor activo en este momento. En una respuesta al informe del problema, alguien recomendó al investigador que proporcionara un PR él mismo."
      }
    ],
    "id": "CVE-2025-15411",
    "lastModified": "2026-10-01T08:10:00.183",
    "metrics": {
      "cvssMetricV2": [
        {
          "acInsufInfo": false,
          "baseSeverity": "MEDIUM",
          "cvssData": {
            "accessComplexity": "LOW",
            "accessVector": "LOCAL",
            "authentication": "SINGLE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 4.3,
            "confidentialityImpact": "PARTIAL",
            "integrityImpact": "PARTIAL",
            "vectorString": "AV:L/AC:L/Au:S/C:P/I:P/A:P",
            "version": "2.0"
          },
          "exploitabilityScore": 3.1,
          "impactScore": 6.4,
          "obtainAllPrivilege": false,
          "obtainOtherPrivilege": false,
          "obtainUserPrivilege": false,
          "source": "cna@vuldb.com",
          "type": "Secondary",
          "userInteractionRequired": false
        }
      ],
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 3.4,
          "source": "cna@vuldb.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "LOCAL",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.9,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "PROOF_OF_CONCEPT",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "LOW",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "LOW",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "cna@vuldb.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-15411",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-05T21:03:24.165884Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-01T20:15:40.640",
    "references": [
      {
        "source": "cna@vuldb.com",
        "url": "https://github.com/WebAssembly/wabt/"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit",
          "Issue Tracking",
          "Vendor Advisory"
        ],
        "url": "https://github.com/WebAssembly/wabt/issues/2679"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Exploit"
        ],
        "url": "https://github.com/oneafter/1208/blob/main/af1"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Permissions Required",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?ctiid.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?id.339332"
      },
      {
        "source": "cna@vuldb.com",
        "tags": [
          "Third Party Advisory",
          "VDB Entry"
        ],
        "url": "https://vuldb.com/?submit.719825"
      },
      {
        "source": "cna@vuldb.com",
        "url": "https://vuldb.com/?submit.736404"
      }
    ],
    "sourceIdentifier": "cna@vuldb.com",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-119"
          }
        ],
        "source": "cna@vuldb.com",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

wabt: WebAssembly wabt: Memory corruption vulnerability in wasm-decompile component
zetlyn/cve-redhat · 2026-01-01
cvss 7.1 cwe CWE-119 severity moderate source
A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.
zetlyn/cve-nvd · 2026-01-01
cvss 5.3 product wabt status Modified vendor WebAssembly source