Binaryen
Vendor:
First CVE: Jan 29, 2019 · Active for 7 years
25
Total CVEs
More Total CVEs than 95% of tracked products
4.2
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Binaryen over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 29, 2019
7 years ago
Most Recent CVE
May 11, 2026
74 days ago
CVE Severity & Scoring
Binaryen25 CVEs
92%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local10 (40.0%)
Network15 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (16.0%)
Unknown0 (0.0%)
Required21 (84.0%)
Privileges Required
Low3 (12.0%)
High0 (0.0%)
None22 (88.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-8257MEDIUM A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn P | May 11, 2026 | 5.5 | 27 | NO | NO |
CVE-2025-14956HIGH A vulnerability was determined in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReader::readExport of the file src/wasm/wasm-binary.cpp. This man | Dec 19, 2025 | 7.1 | 25 | NO | NO |
CVE-2019-15759MEDIUM An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer dereference in wasm::LocalSet::finalize in wasm/wasm.cpp. A cra | Aug 29, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-15758MEDIUM An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at wasm/wasm.cpp in wasm::asmangle. A crafted input can | Aug 29, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-7154MEDIUM The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misused, triggering an error in cashew::JSPrinter::printAst() in e | Jan 29, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-7152MEDIUM A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (when calling wasm::WasmBinaryBuilder::getFunctionIndexName) in | Jan 29, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-7702MEDIUM A NULL pointer dereference was discovered in wasm::SExpressionWasmBuilder::parseExpression in wasm-s-parser.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation f | Feb 10, 2019 | 6.5 | 21 | NO | NO |
CVE-2025-14957MEDIUM A vulnerability was identified in WebAssembly Binaryen up to 125. This affects the function IRBuilder::makeLocalGet/IRBuilder::makeLocalSet/IRBuilder::makeLocalTee of the file src/ | Dec 19, 2025 | 5.5 | 20 | NO | NO |
CVE-2020-18382MEDIUM Heap-buffer-overflow in /src/wasm/wasm-binary.cpp in wasm::WasmBinaryBuilder::visitBlock(wasm::Block*) in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, lea | Aug 22, 2023 | 6.5 | 20 | NO | NO |
CVE-2020-18378MEDIUM A NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, lea | Aug 22, 2023 | 6.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For Binaryen
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.38.26 | 2 | 6.5 | 0.5% | 0 | 0 |
| 104 | 4 | 5.5 | 0.7% | 0 | 0 |
| 103 | 4 | 6.0 | 0.9% | 0 | 0 |