CVE-2025-6274

LOW

WebAssembly wabt <1.0.37 - DoS

Title source: llm
STIX 2.1

Description

A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp.cc. The manipulation leads to resource consumption. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. A similar issue reported during the same timeframe was disputed by the code maintainer because it might not affect "real world wasm programs". Therefore, this entry might get disputed as well in the future.

Scores

CVSS v3 3.3
EPSS 0.0016
EPSS Percentile 36.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-400 CWE-404
Status published
Products (1)
webassembly/wabt < 1.0.37
Published Jun 19, 2025
Tracked Since Feb 18, 2026