webassembly CVE Vulnerabilities & Metrics

Focus on webassembly vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About webassembly Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with webassembly. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total webassembly CVEs: 34
Earliest CVE date: 29 Jan 2019, 00:29 UTC
Latest CVE date: 23 Oct 2023, 17:15 UTC

Latest CVE reference: CVE-2023-46331

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical webassembly CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.63

Max CVSS: 7.1

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 14
4.0-6.9 19
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS webassembly CVEs

These are the five CVEs with the highest CVSS scores for webassembly, sorted by severity first and recency.

All CVEs for webassembly

CVE-2023-46331 webassembly vulnerability CVSS: 0 23 Oct 2023, 17:15 UTC

WebAssembly wabt 1.0.33 has an Out-of-Bound Memory Read in in DataSegment::IsValidRange(), which lead to segmentation fault.

CVE-2023-46332 webassembly vulnerability CVSS: 0 23 Oct 2023, 16:15 UTC

WebAssembly wabt 1.0.33 contains an Out-of-Bound Memory Write in DataSegment::Drop(), which lead to segmentation fault.

CVE-2020-18382 webassembly vulnerability CVSS: 0 22 Aug 2023, 19:15 UTC

Heap-buffer-overflow in /src/wasm/wasm-binary.cpp in wasm::WasmBinaryBuilder::visitBlock(wasm::Block*) in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-opt.

CVE-2020-18378 webassembly vulnerability CVSS: 0 22 Aug 2023, 19:15 UTC

A NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-as.

CVE-2023-31669 webassembly vulnerability CVSS: 0 23 May 2023, 12:15 UTC

WebAssembly wat2wasm v1.0.32 allows attackers to cause a libc++abi.dylib crash by putting '@' before a quote (").

CVE-2023-31670 webassembly vulnerability CVSS: 0 23 May 2023, 01:15 UTC

An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary.

CVE-2023-27119 webassembly vulnerability CVSS: 0 10 Mar 2023, 02:15 UTC

WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild.

CVE-2023-27117 webassembly vulnerability CVSS: 0 10 Mar 2023, 02:15 UTC

WebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator.

CVE-2023-27116 webassembly vulnerability CVSS: 0 10 Mar 2023, 02:15 UTC

WebAssembly v1.0.29 discovered to contain an abort in CWriter::MangleType.

CVE-2023-27115 webassembly vulnerability CVSS: 0 10 Mar 2023, 02:15 UTC

WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size.

CVE-2022-43283 webassembly vulnerability CVSS: 0 28 Oct 2022, 21:15 UTC

wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write.

CVE-2022-43282 webassembly vulnerability CVSS: 0 28 Oct 2022, 21:15 UTC

wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.

CVE-2022-43281 webassembly vulnerability CVSS: 0 28 Oct 2022, 21:15 UTC

wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size() at /bits/stl_vector.h.

CVE-2022-43280 webassembly vulnerability CVSS: 0 28 Oct 2022, 21:15 UTC

wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.

CVE-2021-46055 webassembly vulnerability CVSS: 4.3 10 Jan 2022, 14:11 UTC

A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).

CVE-2021-46054 webassembly vulnerability CVSS: 4.3 10 Jan 2022, 14:11 UTC

A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).

CVE-2021-46053 webassembly vulnerability CVSS: 4.3 10 Jan 2022, 14:11 UTC

A Denial of Service vulnerability exists in Binaryen 103. The program terminates with signal SIGKILL.

CVE-2021-46052 webassembly vulnerability CVSS: 4.3 10 Jan 2022, 14:11 UTC

A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::Tuple::validate.

CVE-2021-46050 webassembly vulnerability CVSS: 4.3 10 Jan 2022, 14:11 UTC

A Stack Overflow vulnerability exists in Binaryen 103 via the printf_common function.

CVE-2021-46048 webassembly vulnerability CVSS: 4.3 10 Jan 2022, 14:11 UTC

A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::readFunctions.

CVE-2021-45293 webassembly vulnerability CVSS: 4.3 21 Dec 2021, 18:15 UTC

A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinaryBuilder::visitLet.

CVE-2021-45290 webassembly vulnerability CVSS: 5.0 21 Dec 2021, 18:15 UTC

A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.

CVE-2019-15759 webassembly vulnerability CVSS: 4.3 29 Aug 2019, 02:15 UTC

An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer dereference in wasm::LocalSet::finalize in wasm/wasm.cpp. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm2js.

CVE-2019-15758 webassembly vulnerability CVSS: 4.3 29 Aug 2019, 02:15 UTC

An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at wasm/wasm.cpp in wasm::asmangle. A crafted input can cause denial-of-service, as demonstrated by wasm2js.

CVE-2019-7704 webassembly vulnerability CVSS: 4.3 10 Feb 2019, 22:29 UTC

wasm::WasmBinaryBuilder::readUserSection in wasm-binary.cpp in Binaryen 1.38.22 triggers an attempt at excessive memory allocation, as demonstrated by wasm-merge and wasm-opt.

CVE-2019-7703 webassembly vulnerability CVSS: 4.3 10 Feb 2019, 22:29 UTC

In Binaryen 1.38.22, there is a use-after-free problem in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service via a wasm file, as demonstrated by wasm-merge.

CVE-2019-7702 webassembly vulnerability CVSS: 4.3 10 Feb 2019, 22:29 UTC

A NULL pointer dereference was discovered in wasm::SExpressionWasmBuilder::parseExpression in wasm-s-parser.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-as.

CVE-2019-7701 webassembly vulnerability CVSS: 4.3 10 Feb 2019, 22:29 UTC

A heap-based buffer over-read was discovered in wasm::SExpressionParser::skipWhitespace() in wasm-s-parser.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm2js.

CVE-2019-7700 webassembly vulnerability CVSS: 4.3 10 Feb 2019, 22:29 UTC

A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-merge.

CVE-2019-7662 webassembly vulnerability CVSS: 7.1 09 Feb 2019, 16:29 UTC

An assertion failure was discovered in wasm::WasmBinaryBuilder::getType() in wasm-binary.cpp in Binaryen 1.38.22. This allows remote attackers to cause a denial of service (failed assertion and crash) via a crafted wasm file.

CVE-2019-7154 webassembly vulnerability CVSS: 4.3 29 Jan 2019, 00:29 UTC

The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misused, triggering an error in cashew::JSPrinter::printAst() in emscripten-optimizer/simple_ast.h. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm2js.

CVE-2019-7153 webassembly vulnerability CVSS: 4.3 29 Jan 2019, 00:29 UTC

A NULL pointer dereference was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (when calling wasm::WasmBinaryBuilder::getFunctionIndexName) in Binaryen 1.38.22. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm-opt.

CVE-2019-7152 webassembly vulnerability CVSS: 4.3 29 Jan 2019, 00:29 UTC

A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (when calling wasm::WasmBinaryBuilder::getFunctionIndexName) in Binaryen 1.38.22. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm-opt.

CVE-2019-7151 webassembly vulnerability CVSS: 4.3 29 Jan 2019, 00:29 UTC

A NULL pointer dereference was discovered in wasm::Module::getFunctionOrNull in wasm/wasm.cpp in Binaryen 1.38.22. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm-opt.