← back
CVE-2025-6274

WebAssembly wabt binary-reader-interp.cc OnDataCount resource consumption

CVSS 4.8 MEDIUMEPSS 0.2%CWE-400CWE-404
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.8EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Jun 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp.cc. The manipulation leads to resource consumption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. A similar issue reported during the same timeframe was disputed by the code maintainer because it might not affect "real world wasm programs". Therefore, this entry might get disputed as well in the future.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
WebAssembly · wabt

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →