PatchSiren

WebAssembly CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WebAssembly CVE published 2026-09-13

CVE-2026-90648

CVE-2026-90648 is a high-severity vulnerability in wasm2c, a component of WebAssembly wabt, which allows for sandbox escape in certain situations, primarily on 32-bit platforms. This vulnerability, also known as a 'table flip' attack, occurs when the funcref table allocation fails, leaving table->data as NULL while table->size retains the guest-declared element count. This can lead to arbitrary read and w [truncated]

LOW WebAssembly CVE published 2026-05-11

CVE-2026-8257

CVE-2026-8257 is a low-severity Binaryen flaw that can trigger a reachable assertion in the BrOn parser path. The issue is reported in Binaryen up to 117 and is tied to IRBuilder::makeBrOn in src/wasm/wasm-ir-builder.cpp. Source data indicates the attack is local, with a public exploit reference and a vendor patch available.

LOW WebAssembly CVE published 2026-01-01

CVE-2025-15412

A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The vulnerability has a low CVSS score of 1.9 and is classified as LOW severity. The project has [truncated]

LOW WebAssembly CVE published 2026-01-01

CVE-2025-15411

A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. Unfortunately, the pr [truncated]