Vulnerabilidades en bytecodealliance

52 resultados
Análisis Vexday

Com 50 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o Bytecodealliance apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere um perfil de risco operacional relativamente contido no momento. O tipo de falha mais recorrente é CWE-125 (leitura fora dos limites de buffer), padrão comum em runtimes e compiladores de baixo nível, e três vulnerabilidades atingem severidade crítica, merecendo atenção prioritária nas atualizações. A CVE mais perigosa ativa hoje, CVE-2022-31104, registra EPSS de 0,0163, indicando baixa probabilidade de exploração imediata, mas a ausência de PoCs públicas não elimina o risco em ambientes que executam código não confiável via WebAssembly. O volume de 14 CVEs surgidas nos últimos 90 dias sinaliza ritmo de descoberta relevante, recomendando monitoramento contínuo da cadeia de dependências que utiliza componentes deste vendor.

CVE-2024-43806MEDIUM`rustix::fs::Dir` iterator with the `linux_raw` backend can cause memory explosionEPSS 0.5%CVE-2026-34941MEDIUMWasmtime has a Heap OOB read in component model UTF-16 to latin1+utf16 string transcodingEPSS 0.5%CVE-2021-32629HIGHMemory access due to code generation flaw in Cranelift moduleEPSS 0.5%CVE-2023-30624LOWWasmtime has Undefined Behavior in Rust runtime functionsEPSS 0.4%CVE-2025-62711LOWWasmtime vulnerable to segfault when using component resourcesEPSS 0.4%CVE-2026-34946MEDIUMWasmtime's host panics when Winch compiler executes `table.fill`EPSS 0.4%CVE-2026-34942MEDIUMWasmtime panics when transcoding misaligned utf-16 stringsEPSS 0.4%CVE-2026-34943MEDIUMWasmtime panics when lifting `flags` component valueEPSS 0.4%CVE-2026-34971CRITICALWasmtime miscompiled guest heap access enables sandbox escape on aarch64 CraneliftEPSS 0.4%CVE-2026-34945LOWWasmtime leaks host data with 64-bit tables and WinchEPSS 0.4%CVE-2026-35186MEDIUMWasmtime has an improperly masked return value from `table.grow` with Winch compiler backendEPSS 0.4%CVE-2025-58749LOWWAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT modeEPSS 0.4%CVE-2026-54786LOWWasmtime: Leak in WASIp1 `fd_renumber` implementationEPSS 0.4%CVE-2021-39219MEDIUMWrong type for `Linker`-define functions when used across two `Engine`sEPSS 0.4%CVE-2022-39394LOWwasmtime_trap_code C API function has out of bounds write vulnerabilityEPSS 0.3%CVE-2025-53901LOWWasmtime has host panic with `fd_renumber` WASIp1 functionEPSS 0.3%CVE-2025-64713MEDIUMWebAssembly Micro Runtime frame_offset_bottom array bounds overflow in fast Interpreter mode when handling GET_GLOBAL(I32) followed by if opcodeEPSS 0.3%CVE-2024-30266LOWWasmtime vulnerable to panic when using a dropped extenref-typed element segmentEPSS 0.3%CVE-2021-39216MEDIUMUse after free passing `externref`s to Wasm in WasmtimeEPSS 0.3%CVE-2026-34988LOWWasmtime leaks data between pooling allocator instancesEPSS 0.3%