A vulnerability was determined in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReader::readExport of the file src/wasm/wasm-binary.cpp. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. Patch name: 4f52bff8c4075b5630422f902dd92a0af2c9f398. It is recommended to apply a patch to fix this issue.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-122"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14956.json"
}{
"cpe": "cpe:2.3:a:webassembly:binaryen:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "125"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14956.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "297504919989245700610474729391651764270",
"length": 357
},
"id": "CVE-2025-14956-31b4e4e1",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/webassembly/binaryen/commit/4f52bff8c4075b5630422f902dd92a0af2c9f398",
"target": {
"file": "src/wasm/wasm-binary.cpp",
"function": "WasmBinaryReader::readExpression"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"201480928520681906379950524024727729655",
"334726967807214632206129284775153697474",
"304652278790085127732226364469106342570",
"38127243108464750520046628332426506894",
"71237723187431418267481440117115206607",
"252088095133434476482696689927987076667",
"249611125164174963394737326246462431268",
"1411843634869612402975512596183721162",
"242793103065672669814075219089174268581"
],
"threshold": 0.9
},
"id": "CVE-2025-14956-646ed37d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/webassembly/binaryen/commit/4f52bff8c4075b5630422f902dd92a0af2c9f398",
"target": {
"file": "src/wasm/wasm-binary.cpp"
}
}
]
"2026-08-12T15:13:42Z"