VendorsBytecode Alliancewebassembly_micro_runtimeany version
Vulnerabilities

Bytecode Alliance Webassembly Micro Runtime any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-25431
An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi_compatibility function.
Published 2024-11-08 · Analyzed
8.8EPSS 0.006
CVE-2024-27532
wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types.
Published 2024-11-08 · Analyzed
7.5EPSS 0.005
CVE-2025-64713
WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode
Published 2025-11-25 · Analyzed
7.4EPSS 0.003
CVE-2025-43853
iwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi feature
Published 2025-05-15 · Analyzed
7.0EPSS 0.003
CVE-2025-54126
WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specified
Published 2025-07-29 · Analyzed
6.9EPSS 0.006
CVE-2023-52284
Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled.
Published 2023-12-31 · Modified
5.5EPSS 0.003
CVE-2025-64704
WebAssembly Micro Runtime vulnerable to a segmentation fault in v128.store instruction
Published 2025-11-25 · Analyzed
5.5EPSS 0.002
CVE-2025-58749
WAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode
Published 2025-09-16 · Analyzed
5.3EPSS 0.004