CVE-2025-15572

LOW

wasm3 < 0.5.0 - Memory Leak in NewCodePage Function

Title source: llm
STIX 2.1

Description

A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation leads to memory leak. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Unfortunately, the project has no active maintainer at the moment.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.344934
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.344934
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.752765
Exploit, Issue Tracking issue-tracking
https://github.com/wasm3/wasm3/issues/550

Scores

CVSS v3 3.3
EPSS 0.0016
EPSS Percentile 5.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-401 CWE-404
Status published
Products (1)
wasm3_project/wasm3 < 0.5.0
Published Feb 10, 2026
Tracked Since Feb 18, 2026