Wabt
Vendor:
First CVE: Oct 28, 2022 · Active for 3 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wabt over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 28, 2022
3 years ago
Most Recent CVE
Jan 1, 2026
204 days ago
CVE Severity & Scoring
Wabt11 CVEs
27%
27%
45%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local9 (81.8%)
Network2 (18.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None5 (45.5%)
Unknown0 (0.0%)
Required6 (54.5%)
Privileges Required
Low5 (45.5%)
High0 (0.0%)
None6 (54.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-15412HIGH A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompil | Jan 1, 2026 | 7.8 | 25 | NO | NO |
CVE-2025-15411HIGH A weakness has been identified in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the | Jan 1, 2026 | 7.8 | 25 | NO | NO |
CVE-2025-2368HIGH A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport o | Mar 17, 2025 | 8.8 | 25 | NO | NO |
CVE-2022-43280HIGH wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount. | Oct 28, 2022 | 7.1 | 24 | NO | NO |
CVE-2025-2584MEDIUM A vulnerability was found in WebAssembly wabt 1.0.36. It has been declared as critical. This vulnerability affects the function BinaryReaderInterp::GetReturnCallDropKeepCount of th | Mar 21, 2025 | 6.8 | 20 | NO | NO |
CVE-2023-27119MEDIUM WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild. | Mar 10, 2023 | 5.5 | 20 | NO | NO |
CVE-2022-43283MEDIUM wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write. | Oct 28, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-43282HIGH wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount. | Oct 28, 2022 | 7.1 | 18 | NO | NO |
A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulnerability is the function GetFuncOffset of the file src/interp | Jun 19, 2025 | 3.3 | 14 | NO | NO |
A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp. | Jun 19, 2025 | 3.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Wabt
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0.36 | 2 | 7.8 | 0.5% | 0 | 0 |
| 1.0.29 | 4 | 6.3 | 0.3% | 0 | 0 |