Wasm3 is a lightweight WebAssembly interpreter designed for resource-constrained environments, and its vulnerability footprint centers narrowly on this single project. The recurring weakness classes—out-of-bounds reads and writes, buffer overflows, and improper memory-bounds checking—reflect the memory-safety demands inherent to an interpreter that executes untrusted bytecode, and a meaningful share of the vendor's disclosures reach serious severity. Defenders deploying Wasm3 in embedded or edge contexts should treat memory-safety issues as high-priority and monitor interpreter updates closely; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wasm3 Project over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-34249CRITICAL wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "DeallocateSlot" in wasm3/source/m3_compile.c. | May 6, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-15413HIGH A vulnerability was detected in wasm3 up to 0.5.0. Impacted is the function op_SetSlot_i32/op_CallIndirect of the file m3_exec.h. Performing a manipulation results in memory corrup | Jan 1, 2026 | 7.8 | 25 | NO | NO |
CVE-2022-39974HIGH WASM3 v0.5.0 was discovered to contain a segmentation fault via the component op_Select_i32_srs in wasm3/source/m3_exec.h. | Sep 20, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-28990HIGH WASM3 v0.5.0 was discovered to contain a heap overflow via the component /wabt/bin/poc.wasm. | May 20, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-38592HIGH Wasm3 0.5.0 has a heap-based buffer overflow in op_Const64 (called from EvaluateExpression and m3_LoadModule). | Aug 12, 2021 | 7.5 | 24 | NO | NO |
CVE-2024-27530HIGH wasm3 139076a contains a Use-After-Free in ForEachModule. | Nov 8, 2024 | 8.4 | 23 | NO | NO |
CVE-2024-27529HIGH wasm3 139076a contains memory leaks in Read_utf8. | Nov 8, 2024 | 8.4 | 23 | NO | NO |
CVE-2024-27528HIGH wasm3 139076a suffers from Invalid Memory Read, leading to DoS and potential Code Execution. | Nov 8, 2024 | 8.4 | 23 | NO | NO |
CVE-2024-27527HIGH wasm3 139076a is vulnerable to Denial of Service (DoS). | Nov 8, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-34252HIGH wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "PreserveRegisterIfOccupied" in wasm3/source/m3_compile.c. | May 6, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wasm3 Project.
Media articles that mention a CVE ID that affects a product developed by Wasm3 Project — matched by CVE ID, not by vendor name.