Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webassembly

First CVE: Jan 29, 2019Active for: 7 yearsTotal CVEs: 45
18.3
VTI Score
Low

WebAssembly tooling and runtimes, including the Binaryen compiler, WABT (WebAssembly Binary Toolkit), and related reference implementations, form a niche but strategically important layer in the modern software stack, sitting between high-level languages and execution environments. The vulnerability surface concentrates in memory-safety and bounds-checking weaknesses—reachable assertions, out-of-bounds reads and writes, NULL pointer dereferences, and improper buffer restrictions—that are characteristic of low-level compiler and runtime code handling untrusted binary formats. These flaws span toolchains and runtimes that are embedded in browsers, server-side WebAssembly hosts, and build pipelines, meaning individual disclosures can affect a broad downstream ecosystem despite the vendor's narrow direct product line. Defenders tracking WebAssembly adoption should monitor this vendor's advisories for memory-corruption and validation gaps that could impact any system compiling or executing WebAssembly modules. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
45
Total CVEs
More Total CVEs than 98% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Webassembly over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 29, 2019
7 years ago
Most Recent CVE
May 11, 2026
74 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (45 CVEs).

45 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-8257MEDIUM
A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn P
May 11, 20265.527NONO
CVE-2025-15412HIGH
A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompil
Jan 1, 20267.825NONO
CVE-2025-15411HIGH
A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the
Jan 1, 20267.825NONO
CVE-2025-14956HIGH
A vulnerability was determined in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReader::readExport of the file src/wasm/wasm-binary.cpp. This man
Dec 19, 20257.125NONO
CVE-2025-2368HIGH
A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport o
Mar 17, 20258.825NONO
CVE-2022-43281HIGH
wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size() at /bits/stl_vector.h.
Oct 28, 20227.825NONO
CVE-2023-27117HIGH
WebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator.
Mar 10, 20237.824NONO
CVE-2022-43280HIGH
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.
Oct 28, 20227.124NONO
CVE-2023-31670HIGH
An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary.
May 23, 20237.523NONO
CVE-2019-15759MEDIUM
An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer dereference in wasm::LocalSet::finalize in wasm/wasm.cpp. A cra
Aug 29, 20196.522NONO
View all 45 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products45 CVEs
71%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local26 (57.8%)
Network19 (42.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (95.6%)
High2 (4.4%)
Unknown0 (0.0%)
User Interaction
None10 (22.2%)
Unknown0 (0.0%)
Required35 (77.8%)
Privileges Required
Low8 (17.8%)
High0 (0.0%)
None37 (82.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (45 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webassembly.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webassembly — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webassembly's Products

View all 2 CNAs →

Top CWEs