VendorsBytecode Alliancewebassembly_micro_runtimeall versions
Vulnerabilities

Bytecode Alliance Webassembly Micro Runtime

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2024-25431
An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi_compatibility function.
Published 2024-11-08 · Analyzed
8.8EPSS 0.006
CVE-2023-48105
An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c.
Published 2023-11-22 · Modified
7.5EPSS 0.010
CVE-2024-34251
An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h.
Published 2024-05-06 · Analyzed
7.5EPSS 0.008
CVE-2024-27532
wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types.
Published 2024-11-08 · Analyzed
7.5EPSS 0.005
CVE-2025-64713
WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode
Published 2025-11-25 · Analyzed
7.4EPSS 0.003
CVE-2025-43853
iwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi feature
Published 2025-05-15 · Analyzed
7.0EPSS 0.003
CVE-2025-54126
WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specified
Published 2025-07-29 · Analyzed
6.9EPSS 0.006
CVE-2024-34250
A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "wasm_loader_check_br" function in core/iwasm/interpreter/wasm_loader.c.
Published 2024-05-06 · Analyzed
6.2EPSS 0.003
CVE-2023-52284
Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled.
Published 2023-12-31 · Modified
5.5EPSS 0.003
CVE-2025-64704
WebAssembly Micro Runtime vulnerable to a segmentation fault in v128.store instruction
Published 2025-11-25 · Analyzed
5.5EPSS 0.002
CVE-2025-58749
WAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode
Published 2025-09-16 · Analyzed
5.3EPSS 0.004