📦 Webassembly Micro Runtime

by Bytecodealliance

🔍 What is Webassembly Micro Runtime?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-27532

HIGH CVSS 7.5 Nov 8, 2024

A NULL pointer dereference vulnerability in wasm-micro-runtime's block_type_get_result_types function allows attackers to cause denial of service or potentially execute arbitrary code. This affects sy...

CVE-2024-34251

HIGH CVSS 7.5 May 6, 2024

An out-of-bounds memory read vulnerability in Bytecode Alliance wasm-micro-runtime v2.0.0 allows remote attackers to cause denial of service by exploiting the block_type_get_arity function. This affec...

CVE-2023-48105

HIGH CVSS 7.5 Nov 22, 2023

A heap overflow vulnerability in Bytecode Alliance's wasm-micro-runtime version 1.2.3 allows remote attackers to cause denial of service by exploiting the wasm_loader_prepare_bytecode function. This a...

CVE-2025-64704

MEDIUM CVSS 4.7 Nov 25, 2025

This vulnerability in WebAssembly Micro Runtime (WAMR) allows a segmentation fault to be triggered via a specially crafted v128.store instruction in WebAssembly modules. This affects any application o...

CVE-2025-58749

MEDIUM CVSS 5.3 Sep 16, 2025

This vulnerability in WebAssembly Micro Runtime (WAMR) causes runtime hangs or crashes when executing WebAssembly programs with specific memory.fill instructions in LLVM-JIT mode. It affects users run...

CVE-2025-54126

MEDIUM CVSS 5.3 Jul 29, 2025

The WebAssembly Micro Runtime's iwasm package in versions 2.4.0 and below incorrectly handles IPv4 addresses without subnet masks in the --addr-pool parameter, causing the service to accept connection...