Known vulnerabilities in wasm-micro-runtime
Vendor:
Bytecode Alliance
Software:
wasm-micro-runtime
Software CPE:
cpe:2.3:a:bytecode_alliance:wasm-micro-runtime:*:*:*:*:*:*:*:*
Website:
https://bytecodealliance.org/
Total vulnerabilities:
8
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (8)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU140983 - Out-of-bounds write CVE-2026-54912 |
CWE-787 | Medium | 2.4.5 | 05.08.2026 |
SB2026080123 |
||
| #VU140982 - Use of Uninitialized Variable CVE-2026-54913 |
CWE-457 | Medium | 2.4.5 | 05.08.2026 |
SB2026080123 |
||
| #VU140705 - Heap-based Buffer Overflow CVE-2026-54914 |
CWE-122 | High | 2.4.5 | 01.08.2026 |
SB2026080123 |
||
| #VU127501 - Out-of-bounds read CVE-2025-64713 |
CWE-125 | Low | 2.4.3 | 24.04.2026 |
SB2026042475 |
||
| #VU127500 - Improper input validation CVE-2025-64704 |
CWE-20 | Medium | 2.4.4 | 24.04.2026 |
SB2026042474 |
||
| #VU127499 - NULL Pointer Dereference CVE-2025-58749 |
CWE-476 | Low | 2.4.2 | 24.04.2026 |
SB2026042473 |
||
| #VU127497 - Improper Access Control CVE-2025-54126 |
CWE-284 | Medium | 2.4.1 | 24.04.2026 |
SB2026042472 |
||
| #VU127496 - Improper Link Resolution Before File Access ('Link Following') CVE-2025-43853 |
CWE-59 | Low | 2.3.0 | 24.04.2026 |
SB2026042471 |