CVE-2025-6274 describes a resource consumption vulnerability in WebAssembly wabt versions up to 1.0.37, specifically within the OnDataCount function of src/interp/binary-reader-interp.cc. This issue, classified as problematic, requires local access for exploitation. With a low CVSS score of 3.3, the vulnerability primarily impacts availability, potentially leading to denial of service. While publicly disclosed, there is no evidence of active exploitation, readily available exploit code, or significant community discussion, and its real-world impact is debated by maintainers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.37CPE matchmatch criteria | cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.