A use-after-free vulnerability has been discovered in the linear memory implementation of Wasmi. This issue can be triggered by a WebAssembly module under certain memory growth conditions, potentially leading to memory corruption, information disclosure, or code execution.
Wasmi v0.41.0 through Wasmi v1.0.0.
This vulnerability was discovered by Robert T. Morris (RTM).
{
"severity": "HIGH",
"cwe_ids": [
"CWE-416"
],
"github_reviewed_at": "2025-12-08T22:15:49Z",
"nvd_published_at": "2025-12-09T16:18:21Z",
"github_reviewed": true
}