Description
A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.
Problem types
Product status
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.20
1.0.21
1.0.22
1.0.23
1.0.24
1.0.25
1.0.26
1.0.27
1.0.28
1.0.29
1.0.30
1.0.31
1.0.32
1.0.33
1.0.34
1.0.35
1.0.36
1.0.37
1.0.38
1.0.39
Timeline
| 2026-01-01: | Advisory disclosed |
| 2026-01-01: | VulDB entry created |
| 2026-01-01: | VulDB entry last update |
Credits
Oneafter (VulDB User)
References
vuldb.com/?id.339333 (VDB-339333 | WebAssembly wabt wasm-decompile VarName out-of-bounds)
vuldb.com/?ctiid.339333 (VDB-339333 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.719826 (Submit #719826 | WebAssembly wabt 1.0.39 and master-branch Memory Corruption)
github.com/WebAssembly/wabt/issues/2678
github.com/oneafter/1208/blob/main/af1
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.