bytecodealliance records
55 published records for vendor bytecodealliance.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 85.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read8
- CWE-416 Use After Free5
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-400 Uncontrolled Resource Consumption3
- CWE-787 Out-of-bounds Write3
- CWE-193 Off-by-one Error2
The weakness classes this vendor ships most often: where to look.
CWEAll records
55 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-26489No exploit | Guest-controlled out-of-bounds read/write on x86_64 in wasmtimebytecodealliance · cranelift-codegen · CWE-125 | Critical9.9 | — | 1.3% | Mar 8, 2023 |
39Monitor | CVE-2022-24791No exploit | Use after free in Wasmtimebytecodealliance · wasmtime · CWE-416 | Critical9.8 | — | 1.2% | Mar 31, 2022 |
39Monitor | CVE-2022-39394No exploit | wasmtime_trap_code C API function has out of bounds write vulnerabilitybytecodealliance · wasmtime · CWE-787 | Critical9.8 | — | 0.3% | Nov 10, 2022 |
36Monitor | CVE-2026-34987No exploit | Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory accessbytecodealliance · wasmtime · CWE-125 | Critical9.0 | — | 0.5% | Apr 9, 2026 |
36Monitor | CVE-2026-34971No exploit | Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Craneliftbytecodealliance · wasmtime · CWE-125 | Critical9.0 | — | 0.4% | Apr 9, 2026 |
35Monitor | CVE-2022-31146No exploit | Use After Free in Wasmtimebytecodealliance · cranelift-codegen · CWE-416 | High8.8 | — | 1.2% | Jul 21, 2022 |
35Monitor | CVE-2021-32629No exploit | Memory access due to code generation flaw in Cranelift modulebytecodealliance · cranelift-codegen · CWE-788 | High8.8 | — | 0.5% | May 24, 2021 |
35Monitor | CVE-2023-30624No exploit | Wasmtime has Undefined Behavior in Rust runtime functionsbytecodealliance · wasmtime · CWE-758 | High8.8 | — | 0.5% | Apr 27, 2023 |
34Monitor | CVE-2022-39393No exploit | Wasmtime vulnerable to data leakage between instances in the pooling allocatorbytecodealliance · wasmtime · CWE-226 | High8.6 | — | 0.7% | Nov 10, 2022 |
32Monitor | CVE-2021-43790No exploit | Use After Free in lucetbytecodealliance · lucet · CWE-416 | High8.1 | — | 1.6% | Nov 29, 2021 |
32Monitor | CVE-2022-23636Proof of concept | Invalid drop of partially-initialized instances in wasmtimebytecodealliance · wasmtime · CWE-824 | High8.1 | — | 0.8% | Feb 16, 2022 |
31Monitor | CVE-2024-25431No exploit | An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privilegesbytecodealliance · webassembly micro runtime · CWE-125 | High7.8 | — | 0.6% | Nov 8, 2024 |
30Monitor | CVE-2023-48105No exploit | An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of bytecodealliance · webassembly micro runtime · CWE-787 | High7.5 | — | 1.0% | Nov 22, 2023 |
30Monitor | CVE-2022-31169No exploit | Cranelift vulnerable to miscompilation of constant values in division on AArch64bytecodealliance · cranelift-codegen · CWE-682 | High7.5 | — | 0.9% | Jul 22, 2022 |
30Monitor | CVE-2024-34251No exploit | An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cabytecodealliance · webassembly micro runtime · CWE-125 | High7.5 | — | 0.8% | May 6, 2024 |
30Monitor | CVE-2024-27532No exploit | wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_resbytecodealliance · webassembly micro runtime · CWE-476 | High7.5 | — | 0.5% | Nov 8, 2024 |
30Monitor | CVE-2026-47261No exploit | Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restrictionbytecodealliance · wasmtime · CWE-284 | High7.5 | — | 0.5% | Jun 15, 2026 |
29Monitor | CVE-2022-39392No exploit | Wasmtime vulnerable to out of bounds read/write with zero-memory-pages configurationbytecodealliance · wasmtime · CWE-119 | High7.4 | — | 0.6% | Nov 10, 2022 |
29Monitor | CVE-2025-64713No exploit | WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcodebytecodealliance · webassembly micro runtime · CWE-119 | High7.4 | — | 0.3% | Nov 25, 2025 |
28Monitor | CVE-2025-43853No exploit | iwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi featurebytecodealliance · webassembly micro runtime · CWE-61 | High7.0 | — | 0.3% | May 15, 2025 |
27Monitor | CVE-2026-27572No exploit | Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instancebytecodealliance · wasmtime · CWE-770 | Medium6.9 | — | 0.7% | Feb 24, 2026 |
27Monitor | CVE-2026-27204No exploit | Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustionbytecodealliance · wasmtime · CWE-400 | Medium6.9 | — | 0.7% | Feb 24, 2026 |
27Monitor | CVE-2025-54126No exploit | WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specifiedbytecodealliance · webassembly micro runtime · CWE-668 | Medium6.9 | — | 0.6% | Jul 29, 2025 |
27Monitor | CVE-2026-27195No exploit | Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` futurebytecodealliance · wasmtime · CWE-755 | Medium6.9 | — | 0.6% | Feb 24, 2026 |
27Monitor | CVE-2026-34941No exploit | Wasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcodingbytecodealliance · wasmtime · CWE-125 | Medium6.9 | — | 0.5% | Apr 9, 2026 |
- CVE-2023-2648939Monitor
Guest-controlled out-of-bounds read/write on x86_64 in wasmtime
CriticalCVSS 9.9No exploitEPSS 1%bytecodealliance · cranelift-codegenMar 8, 2023
- CVE-2022-2479139Monitor
Use after free in Wasmtime
CriticalCVSS 9.8No exploitEPSS 1%bytecodealliance · wasmtimeMar 31, 2022
- CVE-2022-3939439Monitor
wasmtime_trap_code C API function has out of bounds write vulnerability
CriticalCVSS 9.8No exploitEPSS 0%bytecodealliance · wasmtimeNov 10, 2022
- CVE-2026-3498736Monitor
Wasmtime with Winch compiler backend on aarch64 may allow a sandbox-escaping memory access
CriticalCVSS 9.0No exploitEPSS 0%bytecodealliance · wasmtimeApr 9, 2026
- CVE-2026-3497136Monitor
Wasmtime miscompiled guest heap access enables sandbox escape on aarch64 Cranelift
CriticalCVSS 9.0No exploitEPSS 0%bytecodealliance · wasmtimeApr 9, 2026
- CVE-2022-3114635Monitor
Use After Free in Wasmtime
HighCVSS 8.8No exploitEPSS 1%bytecodealliance · cranelift-codegenJul 21, 2022
- CVE-2021-3262935Monitor
Memory access due to code generation flaw in Cranelift module
HighCVSS 8.8No exploitEPSS 0%bytecodealliance · cranelift-codegenMay 24, 2021
- CVE-2023-3062435Monitor
Wasmtime has Undefined Behavior in Rust runtime functions
HighCVSS 8.8No exploitEPSS 0%bytecodealliance · wasmtimeApr 27, 2023
- CVE-2022-3939334Monitor
Wasmtime vulnerable to data leakage between instances in the pooling allocator
HighCVSS 8.6No exploitEPSS 1%bytecodealliance · wasmtimeNov 10, 2022
- CVE-2021-4379032Monitor
Use After Free in lucet
HighCVSS 8.1No exploitEPSS 2%bytecodealliance · lucetNov 29, 2021
- CVE-2022-2363632Monitor
Invalid drop of partially-initialized instances in wasmtime
HighCVSS 8.1Proof of conceptEPSS 1%bytecodealliance · wasmtimeFeb 16, 2022
- CVE-2024-2543131Monitor
An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges
HighCVSS 7.8No exploitEPSS 1%bytecodealliance · webassembly micro runtimeNov 8, 2024
- CVE-2023-4810530Monitor
An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of
HighCVSS 7.5No exploitEPSS 1%bytecodealliance · webassembly micro runtimeNov 22, 2023
- CVE-2022-3116930Monitor
Cranelift vulnerable to miscompilation of constant values in division on AArch64
HighCVSS 7.5No exploitEPSS 1%bytecodealliance · cranelift-codegenJul 22, 2022
- CVE-2024-3425130Monitor
An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to ca
HighCVSS 7.5No exploitEPSS 1%bytecodealliance · webassembly micro runtimeMay 6, 2024
- CVE-2024-2753230Monitor
wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_res
HighCVSS 7.5No exploitEPSS 1%bytecodealliance · webassembly micro runtimeNov 8, 2024
- CVE-2026-4726130Monitor
Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
HighCVSS 7.5No exploitEPSS 1%bytecodealliance · wasmtimeJun 15, 2026
- CVE-2022-3939229Monitor
Wasmtime vulnerable to out of bounds read/write with zero-memory-pages configuration
HighCVSS 7.4No exploitEPSS 1%bytecodealliance · wasmtimeNov 10, 2022
- CVE-2025-6471329Monitor
WebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcode
HighCVSS 7.4No exploitEPSS 0%bytecodealliance · webassembly micro runtimeNov 25, 2025
- CVE-2025-4385328Monitor
iwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi feature
HighCVSS 7.0No exploitEPSS 0%bytecodealliance · webassembly micro runtimeMay 15, 2025
- CVE-2026-2757227Monitor
Wasmtime can panic when adding excessive fields to a `wasi:http/types.fields` instance
MediumCVSS 6.9No exploitEPSS 1%bytecodealliance · wasmtimeFeb 24, 2026
- CVE-2026-2720427Monitor
Wasmtime WASI implementations are vulnerable to guest-controlled resource exhaustion
MediumCVSS 6.9No exploitEPSS 1%bytecodealliance · wasmtimeFeb 24, 2026
- CVE-2025-5412627Monitor
WebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specified
MediumCVSS 6.9No exploitEPSS 1%bytecodealliance · webassembly micro runtimeJul 29, 2025
- CVE-2026-2719527Monitor
Wasmtime is vulnerable to panic when dropping a `[Typed]Func::call_async` future
MediumCVSS 6.9No exploitEPSS 1%bytecodealliance · wasmtimeFeb 24, 2026
- CVE-2026-3494127Monitor
Wasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding
MediumCVSS 6.9No exploitEPSS 0%bytecodealliance · wasmtimeApr 9, 2026