CVE-2025-15412

Source
https://cve.org/CVERecord?id=CVE-2025-15412
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15412.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-15412
Downstream
Published
2026-01-01T20:32:06.684Z
Modified
2026-07-15T01:48:51.673007864Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
WebAssembly wabt wasm-decompile VarName out-of-bounds
Details

A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.

Database specific
{
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15412.json",
    "cwe_ids": [
        "CWE-119",
        "CWE-125"
    ]
}
References

Affected packages

Git / github.com/webassembly/wabt

Affected ranges

Type
GIT
Repo
https://github.com/webassembly/wabt
Events
Database specific
{
    "cpe": "cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "last_affected": "1.0.0"
        },
        {
            "introduced": "1.0.1"
        },
        {
            "last_affected": "1.0.1"
        },
        {
            "introduced": "1.0.2"
        },
        {
            "last_affected": "1.0.2"
        },
        {
            "introduced": "1.0.3"
        },
        {
            "last_affected": "1.0.3"
        },
        {
            "introduced": "1.0.4"
        },
        {
            "last_affected": "1.0.4"
        },
        {
            "introduced": "1.0.5"
        },
        {
            "last_affected": "1.0.5"
        },
        {
            "introduced": "1.0.6"
        },
        {
            "last_affected": "1.0.6"
        },
        {
            "introduced": "1.0.7"
        },
        {
            "last_affected": "1.0.7"
        },
        {
            "introduced": "1.0.8"
        },
        {
            "last_affected": "1.0.8"
        },
        {
            "introduced": "1.0.9"
        },
        {
            "last_affected": "1.0.9"
        },
        {
            "introduced": "1.0.10"
        },
        {
            "last_affected": "1.0.10"
        },
        {
            "introduced": "1.0.11"
        },
        {
            "last_affected": "1.0.11"
        },
        {
            "introduced": "1.0.12"
        },
        {
            "last_affected": "1.0.12"
        },
        {
            "introduced": "1.0.13"
        },
        {
            "last_affected": "1.0.13"
        },
        {
            "introduced": "1.0.14"
        },
        {
            "last_affected": "1.0.14"
        },
        {
            "introduced": "1.0.15"
        },
        {
            "last_affected": "1.0.15"
        },
        {
            "introduced": "1.0.16"
        },
        {
            "last_affected": "1.0.16"
        },
        {
            "introduced": "1.0.17"
        },
        {
            "last_affected": "1.0.17"
        },
        {
            "introduced": "1.0.18"
        },
        {
            "last_affected": "1.0.18"
        },
        {
            "introduced": "1.0.19"
        },
        {
            "last_affected": "1.0.19"
        },
        {
            "introduced": "1.0.20"
        },
        {
            "last_affected": "1.0.20"
        },
        {
            "introduced": "1.0.21"
        },
        {
            "last_affected": "1.0.21"
        },
        {
            "introduced": "1.0.22"
        },
        {
            "last_affected": "1.0.22"
        },
        {
            "introduced": "1.0.23"
        },
        {
            "last_affected": "1.0.23"
        },
        {
            "introduced": "1.0.24"
        },
        {
            "last_affected": "1.0.24"
        },
        {
            "introduced": "1.0.25"
        },
        {
            "last_affected": "1.0.25"
        },
        {
            "introduced": "1.0.26"
        },
        {
            "last_affected": "1.0.26"
        },
        {
            "introduced": "1.0.27"
        },
        {
            "last_affected": "1.0.27"
        },
        {
            "introduced": "1.0.28"
        },
        {
            "last_affected": "1.0.28"
        },
        {
            "introduced": "1.0.29"
        },
        {
            "last_affected": "1.0.29"
        },
        {
            "introduced": "1.0.30"
        },
        {
            "last_affected": "1.0.30"
        },
        {
            "introduced": "1.0.31"
        },
        {
            "last_affected": "1.0.31"
        },
        {
            "introduced": "1.0.32"
        },
        {
            "last_affected": "1.0.32"
        },
        {
            "introduced": "1.0.33"
        },
        {
            "last_affected": "1.0.33"
        },
        {
            "introduced": "1.0.34"
        },
        {
            "last_affected": "1.0.34"
        },
        {
            "introduced": "1.0.35"
        },
        {
            "last_affected": "1.0.35"
        },
        {
            "introduced": "1.0.36"
        },
        {
            "last_affected": "1.0.36"
        },
        {
            "introduced": "1.0.37"
        },
        {
            "last_affected": "1.0.37"
        },
        {
            "introduced": "1.0.38"
        },
        {
            "last_affected": "1.0.38"
        },
        {
            "introduced": "1.0.39"
        },
        {
            "last_affected": "1.0.39"
        },
        {
            "introduced": "0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

1.*
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.2
1.0.20
1.0.21
1.0.22
1.0.23
1.0.24
1.0.25
1.0.26
1.0.27
1.0.28
1.0.29
1.0.3
1.0.30
1.0.31
1.0.32
1.0.33
1.0.34
1.0.35
1.0.36
1.0.37
1.0.38
1.0.39
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Other
gh-actions-test
gh-actions-test2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15412.json"